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NOTE 
From: Incoming Presidency 
To: Law Enforcement Working Party (Police) 


No. prev. doc.: 9068/22, 12354/22, 14008/22, 14143/22; 6276/23; 7038/23; 7595/23; 
7842/23; 8845/23; 9317/23; 9971/23 


Subject: Proposal for a Regulation of the European Parliament and of the Council 
laying down rules to prevent and combat child sexual abuse 


— Presidency compromise texts 


With a view to the Law Enforcement Working Party (Police) meeting on 5 July 2023, delegations 


will find in the Annex Presidency compromise texts on the above proposal. 


The main changes proposed compared to document 9971/23 discussed in the LEWP meeting of 


13 June are the following: 
e Reinforcement of the risk assessment/mitigation and the targetting of the detection orders: 


o Reinforced risk assessments/mitigation/reporting to further ensure that the detection orders 


are a measure of last resort (Articles 3-5a). 
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o New Article 5a to further clarify that the mitigation measures are exhausted before the 


detection orders can be considered. 


o New Article 5b, (previous Article 6a), on the sign of compliance with the risk assessment, 


further developed. 


o New Article 3(4a) to gather information about the exact nature of the risk, to facilitate 
putting in place mitigation measures as targeted as possible. This information about the risk 


can be used for targeting the detection orders as much as possible. 
o Further specification of “significant risk” (Article 7). 


o Deletion of “other independent administrative authorities” so that only judiciary authority 


can issue detection orders. 


e Technological neutrality (including encryption): new wording to take into account the 


comments in the last LEWP meeting. 
e (Cross-border) removal orders: alignment with the existing TCO model (Articles 14 and 14a). 
e EU Centre: 

co further development of the provisions on prevention (Article 43); 


o further development of the provisions on prevention on the Technology Committee (Article 


50); 


o following the deletion of the Executive Board and the transfer of all its tasks to the 
Management Board (Article 57), Presidency proposal to grant enhanced powers to the 


Commission on budgetary matters (Article 60). 
Changes to the Commission proposal are marked in bold and strikethrough. 


New changes to the Commission proposal in comparison to document 9971/23 are marked in bold 


underline and strikethrough underline. 
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ANNEX 


Proposal for a 
REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL 


laying down rules to prevent and combat child sexual abuse 


(Text with EEA relevance) 
CHAPTERI 
GENERAL PROVISIONS 
Article 1 


Subject matter and scope 


1. This Regulation lays down uniform rules to prevent and combat address in a targeted, 
carefully balanced and proportionate manner the misuse of relevant information society 
services for online child sexual abuse in the internal market. 


It establishes, in particular: 


(a) obligations on providers of relevant information society services to minimise the risk 
that their services are misused for online child sexual abuse; 


(b) obligations on providers of hosting services and providers of interpersonal 
communications services to detect and report online child sexual abuse; 


(c) obligations on providers of hosting services to remove or disable access to child 
sexual abuse material on their services; 


(d) obligations on providers of internet access services to prevent users from accessing 
aecess child sexual abuse material; 


(da) obligations on providers of online search engines to delist websites indicating 
specific items of child sexual abuse; 


(ce) rules on the implementation and enforcement of this Regulation, including as regards 
the designation and functioning of the competent authorities of the Member States, 
the EU Centre on Child Sexual Abuse established in Article 40 ((EU Centre’) and 
cooperation and transparency. 
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2 This Regulation shall apply to providers of relevant information society services offering 
such services in the Union, irrespective of their place of main establishment. 


3, This Regulation shall not affect the rules laid down by the following legal acts: 


(a) Directive 2011/93/EU on combating the sexual abuse and sexual exploitation of 
children and child pornography, and replacing Council Framework Decision 
2004/68/JHA; 


Rist scl eel éould ey adda 


To address the comments of a delegation in relation to national security, classified 
information, professional secrecy and trade secrets, the following recital could be added: 


“Tn the light of the more limited risk of their use for the purpose of child sexual abuse and the 
need to preserve confidential information, including classified information, information 
covered by professional secrecy and trade secrets, electronic communications services that are 
not publicly available should be excluded from the scope of this Regulation. Accordingly, this 
Regulation should not apply to interpersonal communications services that are not available to 
the general public and the use of which is instead restricted to persons involved in the 
activities of a particular company, organisation, body or authority.” 


achernative end due-to-the tactics for-de -the-se ofthe Res 


use of which ig instead restricted to- persone involved in the activities ofa parti wlarcompany, 
+4 — | +] He? 
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(b) Directive 2000/31/EC and Regulation (EU) .../... [on a Single Market For Digital 
Services (Digital Services Act) and amending Directive 2000/3 1/EC]; 


(ba) Regulation (EU) 2022/... of ... on contestable and fair markets in the digital 
sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital 
Markets Act); 


(c) Directive 2010/13/EU; 


(d) Regulation (EU) 2016/679, Directive 2016/680, Regulation (EU) 2018/1725, and, 
subject to paragraph 4 of this Article, Directive 2002/58/EC; 


(e) Regulation (EU) 2021/784 of the European Parliament and of the Council of 29 
April 2021 on addressing the dissemination of terrorist content online. 


3a. This Regulation shall not have the effect of modifying the obligation to respect the 
rights, freedoms and principles referred to in Article 6 TEU and shall apply without 
prejudice to fundamental principles relating to the right for respect to private life and 
family life and to freedom of expression and information.” 


4. This Regulation limits the exercise of the rights and obligations provided for in 5(1) and 
(3) and Article 6(1) of Directive 2002/58/EC to the extent strictly insefaras-necessary for 
the execution of the detection orders issued in accordance with Section 2 of Chapter + II of 
this Regulation. 


Wording copied from Art. 1(4) of TCO Regulation with an additional reference to the right to 
private life. 


3 PCY comment: cer ro, ‘notes thatthe eee Selneen oe 


ee dane the ‘Howeal penient 
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wheter provision ofthis kind should rather finds piven Ac 103) an hse 


a 9 ) Q Q 


heat she ted peacided henrecial 26. 


PCY comment: on the basis of the political guidance provided by Coreper on 31 May and of 
the discussions in the LEWP meeting of 13 June, the following additions are proposed to 
recital 26 in relation to encryption: 


“The measures taken by providers of hosting services and providers of publicly available 
interpersonal communications services to execute detection orders addressed to them should 
remain strictly limited to what is specified in this Regulation and in the detection orders 
issued in accordance with this Regulation. In order to ensure the effectiveness of those 
measures, allow for tailored solutions, remain technologically neutral, and avoid 
circumvention of the detection obligations, those measures should be taken regardless of the 
technologies used by the providers concerned in connection to the provision of their services. 
Therefore, this Regulation leaves to the provider concerned the choice of the technologies to 
be operated to comply effectively with detection orders and should not be understood as 
incentivising or disincentivising the use of any given technology, provided that the 
technologies and accompanying measures meet the requirements of this Regulation. That 
includes the use of end-to-end encryption technology, which is an important tool to guarantee 
the security and confidentiality of the communications of users, including those of children. 


Having regard to the availability of technologies that_can_be used to meet the 
requirements of this Regulation whilst still allowing for end-to-end encryption, nothing 


in this Regulation should be interpreted as prohibiting or making end-to-end encryption 
impossible. When executing the detection order, providers should take all available safeguard 


measures to ensure that the technologies employed by them cannot be used by them or their 
employees for purposes other than compliance with this Regulation, nor by third parties, and 
thus to avoid undermining the security and confidentiality of the communications of users, 


while ensuring the effective detection of online child sexual abuse and the fair balance of 
all the fundamental rights at stake.” 


if rsecurity measures_in reular-ener tee 1es ine in2-end-to-end 


while the-datais essedin transit or stored by the service Hder.” 
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Article 2 


Definitions 


For the purpose of this Regulation, the following definitions apply: 


(a) ‘hosting service’ means an information society service as defined in Article 2, point (f), 
third indent, of Regulation (EU) .../... fon a Single Market For Digital Services (Digital 
Services Act) and amending Directive 2000/3 1/EC]; 


(b) ‘interpersonal communications service’ means a publicly available service as defined in 
Article 2, point 5, of Directive (EU) 2018/1972, including services which enable direct 
interpersonal and interactive exchange of information merely as a minor ancillary feature 
that is intrinsically linked to another service; 


(c) ‘software application’ means a digital product or service as defined in Article 2, point 13, 
of Regulation (EU) .../... [on contestable and fair markets in the digital sector (Digital 
Markets Act)|; 

(d) ‘software application store’ means a service as defined in Article 2, point 12, of Regulation 


(EU) .../... [on contestable and fair markets in the digital sector (Digital Markets Act)] ; 


(e) ‘internet access service’ means a service as defined in Article 2(2), point 2, of Regulation 
(EU) 2015/2120 of the European Parliament and of the Council®; 


(f) ‘relevant information society services’ means all of the following services: 
(i) a hosting service; 
(ii) an interpersonal communications service; 
(iii) a software applications store; 
(iv) an internet access service; 
(v) online search engines. 


(g) ‘to offer services in the Union’ means to offer services in the Union as defined in Article 2, 
point (d), of Regulation (EU) .../... [on a Single Market For Digital Services (Digital 
Services Act) and amending Directive 2000/3 1/EC]; 


(h) ‘user’ means any natural or legal person who uses a relevant information society service; 


(1) ‘child’ means any natural person below the age of 18 years; 


. Regulation (EU) 2015/2120 of the European Parliament and of the Council of 25 November 
2015 laying down measures concerning open internet access and amending Directive 
2002/22/EC on universal service and users’ rights relating to electronic communications 
networks and services and Regulation (EU) No 531/2012 on roaming on public mobile 
communications networks within the Union (OJ L 310, 26.11.2015, p. 1-18). 
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q) ‘child user’ means a natural person who uses a relevant information socicty service and 
who-is-a natural person below the age of 17 years:’ 

(k) ‘micro, small or medium-sized enterprise’ means an enterprise as defined in Commission 
Recommendation 2003/361 concerning the definition of micro, small and medium-sized 
enterprises®; 

(1) ‘child sexual abuse material’ means: material constituting child pornography or 
pornographic performance as defined in Article 2, points (c) and (e), respectively, of 
Directive 2011/93/EU; 

(m) ‘known child sexual abuse material’ means potential child sexual abuse material detected 
using the indicators contained in the database of indicators referred to in Article 44(1), 
point (a); 

(n) ‘new child sexual abuse material’ means potential child sexual abuse material detected 
using the indicators contained in the database of indicators referred to in Article 44(1), 
point (b); 

(0) ‘solicitation of children’ means the solicitation of children for sexual purposes as referred 
to in Article 6 of Directive 201 1/93/EU; 

(p) ‘online child sexual abuse’ means the online dissemination of child sexual abuse material 
and the solicitation of children; 

(q) ‘child sexual abuse offences’ means offences as defined in Articles 3 to 7 of Directive 
2011/93/EU; 

(r) ‘recommender system’ means the system as defined in Article 2, point (0), of Regulation 
(EU) .../... fon a Single Market For Digital Services (Digital Services Act) and amending 
Directive 2000/3 1/EC]; 

(s) ‘content data’ means data as defined in Article 2, point 10, of Regulation (EU) ... [on 
European Production and Preservation Orders for electronic evidence in criminal matters 
(.../... e-evidence Regulation) ]; 

- PCY comment: The PCY concludes that differences in national law for instance, the age used 
for defining solicitation make it necessary to find common ground in order to avoid disparities 
in the application of the Regulation. 

: Commission Recommendation of 6 May 2003 concerning the definition of micro, small and 
medium-sized enterprises (OJ L 124, 20.5.2003, p. 36-41). 
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(t) 


(u) 


(v) 


(w) 


(x) 


(y) 


‘content moderation’ means the activities as defined in Article 2, point (p), of Regulation 
(EU) .../... fon a Single Market For Digital Services (Digital Services Act) and amending 
Directive 2000/3 1/EC]; 


‘Coordinating Authority of establishment’ means the Coordinating Authority for child 
sexual abuse issues designated in accordance with Article 25 by the Member State where 
the provider of information society services has its main establishment or, where 
applicable, where its legal representative resides or is established;? 


‘terms and conditions’ means terms and conditions as defined in Article 2, point (q), of 
Regulation (EU) .../... fon a Single Market For Digital Services (Digital Services Act) and 
amending Directive 2000/3 1/EC]; 


‘main establishment’ means the head office or registered office of the provider of relevant 
information society services within which the principal financial functions and operational 
control are exercised; 


‘online search engine’ means an intermediary service as defined in Article 3, point (j), 
of Regulation (EU) .../... [on a Single Market For Digital Services (Digital Services 
Act) and amending Directive 2000/31/EC]; 


6 b 


concerned to iiersei ith each others ith neclcible debi: 


‘call’ means _a_ connection as defined in Article 2, point 31 of Directive (EU) 
2018/1972; 


PCY comment: the PCY would like to hear the views of delegations on the possible need to 


align the references in Articles 3 to 6 with the new logic of designating competent and 
Coordinating Authorities according to Articles 25 and 26 taking full account of the role 
envisaged by the Coordinating Authorities also in connection to the detection orders. 
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CHAPTERII 
OBLIGATIONS OF PROVIDERS OF RELEVANT INFORMATION SOCIETY SERVICES 
TO PREVENT AND COMBAT ONLINE CHILD SEXUAL ABUSE 


Section 1 
Risk assessment and mitigation obligations 


Article 3 
Risk assessment 


1. Providers of hosting services and providers of interpersonal communications services shall 
diligently identify, analyse and assess, for each such service that they offer, the risk of use 
of the service for the purpose of online child sexual abuse. 


2 When carrying out a risk assessment, the provider shall take into account, in particular: 


(a) any previously identified instances of use of its services for the purpose of online 
child sexual abuse; 


(b) the existence and implementation by the provider of a policy and the availability of 
functionalities to address the risk referred to in paragraph 1, including through the 
following: 

— prohibitions and restrictions laid down in the terms and conditions; 
— measures taken to enforce such prohibitions and restrictions; 
— functionalities enabling age verification; 


— functionalities enabling parental-centrelor parental consent mechanisms; 


— functionalities enabling users to flag notify online child sexual abuse to the 
provider through tools that are easily accessible and age-appropriate; 


— measures taken to ensure a robust and swift process to handle notified 
potential child sexual abuse; 


— functionalities enabling the providers the compilation and generation of 
relevant statistical information for assessment purposes. 


(c) the manner in which users use the service and the impact thereof on that risk; 


ca) age appropriate measures taken by the provider to promote users’ media 
literacy and safe use of the service; 
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(d) the manner in which the provider designed and operates the service, including the 
business model, governance and relevant systems and processes, and the impact 
thereof on that risk; 


(da) the availability of functionalities enabling users to share images or videos with 
other users, in_ particular through private communications, and_ of 
functionalities enabling the providers to assess how easily, quickly, and widely 
such material may be disseminated further by means of the service; 


(e) with respect to the risk of solicitation of children: 
(1) the extent to which the service is used or is likely to be used by children; 


(11) where the service is used by children, the different age groups of the child 
users and the risk of solicitation of children in relation to those age groups; 


(111) the availability of functionalities creating or reinforcing the risk of solicitation 
of children, including the following functionalities: 


— enabling users to search for other users and, in particular, for adult users 
to search for child users; 


— enabling users to establish contact with other users directly, in particular 
through private communications. 


— enabling users to share images-or videos with other users. in particular 
by ori ae. 
3: The provider may request the EU Centre to perform an analysis of representative, 


anonymized data samples to identify potential online child sexual abuse, to support the risk 
assessment. 


The costs incurred by the EU Centre for the performance of such an analysis shall be borne 
by the requesting provider. However, the EU Centre shall bear those costs where the 
provider is a micro, small or medium-sized enterprise, provided the request is reasonably 
necessary to support the risk assessment. The EU Centre shall make available 


information to providers to determine those costs. 


The Commission shall be empowered to adopt delegated acts in accordance with Article 86 
in order to supplement this Regulation with the necessary detailed rules on the 
determination and charging of those costs, the information to be provided and the 
application of the exemption for micro, small and medium-sized enterprises. 


4. The provider shall carry out the first risk assessment by /Date of application of this 
Regulation + 3 months] or, where the provider did not offer the service in the Union by 
[Date of application of this Regulation], by three months from the date at which the 
provider started offering the service in the Union. 


Subsequently, the provider shall update the risk assessment where necessary and at least 
once every three years from the date at which it last carried out or updated the risk 
assessment. However: 
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(a) 


(b) 


for a service which is subject to a detection order issued in accordance with Article 7, 
the provider shall update the risk assessment at the latest #ve four months before the 
expiry of the period of application of the detection order; 


the Coordinating Authority of establishment may require the provider to update the 
risk assessment at a reasonable earlier date than the date referred to in the second 
subparagraph, where there is evidence indicating a possible substantial change in the 
risk that the service is used for the purpose of online child sexual abuse. 


4a. The risk assessment shall gather information on the limitation of the risk to an 
identifiable part or component of the service where possible, such as specific types of 
channels of an interpersonal communications service, or to specific users or specific 
groups of users where possible, to the extent that such part, component, specific users 


or specific groups of users can be assessed in isolation for the purpose of mitigating 
the risk of online child sexual abuse. 


a: The risk assessment shall include an assessment of any potential remaining risk that, after 
taking the mitigation measures pursuant to Article 4, the service is used for the purpose of 
online child sexual abuse. 


6. The Commission, in cooperation with Coordinating Authorities and the EU Centre and 
after having conducted a public consultation, may issue guidelines on the application of 
paragraphs | to 5, having due regard in particular to relevant technological developments 
and to the manners in which the services covered by those provisions are offered and used. 


Article 4 


Risk mitigation 


1. If providers of hosting services and providers of interpersonal communications services 
have identified a risk of the service being used for the purpose of online child sexual 
abuse pursuant to Article 3, they shall take all reasonable mitigation measures, tailored 


to the that risk identified pursuant+e—Article3, to minimise that risk. The risk mitigation 
measures shall be limited to an identifiable part or component of the service, or to 


specific users or specific groups of users, where possible, without prejudice to the 
effectiveness of the measure. 


Such measures shall at least include some or all of the following: 


(a) 


(b) 


adapting, through appropriate technical and operational measures and staffing, the 
provider’s content moderation or recommender systems, its decision-making 
processes, the operation or functionalities of the service, or the content or 
enforcement of its terms and conditions; 


reinforcing the provider’s internal processes or the internal supervision of the 
functioning of the service; 
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(c) initiating or adjusting cooperation, in accordance with competition law, with other 
providers of hosting services or providers of interpersonal communications services, 
public authorities, civil society organisations or, where applicable, entities awarded 
the status of trusted flaggers in accordance with Article 19 of Regulation (EU) .../... 
[on a Single Market For Digital Services (Digital Services Act) and amending 
Directive 2000/3 1/EC]; 


(d) initiating or adjusting functionalities that enable users to notify online child 
sexual abuse to the provider through tools that are easily accessible and age- 
appropriate; 


(e) initiating or adjusting functionalities that enable users to control what 
information about them is shared to other users and how other users may 
contact them, and introducing default suitable privacy settings for users who 
are minors; 


(f) initiating or adjusting functionalities that provide information to users about 
notification systems mechanisms and direct users to helplines and trusted 


organisations, where users detect material or contact indicating potential online 
child sexual abuse ici : 


initiating or adjusting functionalities that allow the providers to collect 


statistical data to better _assess the risks and the effectiveness of the mitigation 
measures. This data shall not include any personal data. 


2. The mitigation measures shall be: 
(a) effective in mitigating the identified risk; 


(b) targeted and proportionate in relation to that risk, taking into account, in particular, 
the seriousness of the risk as well as the provider’s financial and technological 
capabilities and the number of users; 


(c) applied in a diligent and non-discriminatory manner, having due regard, in all 
circumstances, to the potential consequences of the mitigation measures for the 
exercise of fundamental rights of all parties affected; 


(d) introduced, implemented, reviewed, modified, discontinued or expanded, as 
appropriate, each time the risk assessment is conducted or updated pursuant to 
Article 3(4), within three months from the date referred to therein. 


p. Providers of interpersonal communications services that have identified, pursuant to the 
risk assessment conducted or updated in accordance with Article 3, a risk of use of their 
services for the purpose of the solicitation of children, shall take the necessary age 
verification and age assessment measures to reliably identify child users on their services, 
enabling them to take the mitigation measures. 
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3a. Any Those age verification and age assessment measures shall be privacy preserving, 
proportionate, effective, accurate, non-discriminatory, accessible and take the best 


mitenest ob the chil into Account of the child into account netinyelye-any-profiling or _ biometric identification 
of-users'°, 


3a. The provider _ may request the EU Centre to assist in analysing suitable specific 
mitigation measures. 


The costs incurred by the EU Centre for the performance of such an analysis shall be 
borne by the requesting provider. However, the EU Centre shall bear those costs 
where the provider is _a_ micro, small or medium-sized enterprise, provided the 


request is reasonably necessary to support the risk assessment. The EU Centre shall 
make available information to determine those costs. 


The Commission shall be empowered to adopt delegated acts in accordance with 
Article 86 in order to supplement this Regulation with the necessary detailed rules on 
the determination and charging of those costs, the information to be provided and the 
application of the exemption for micro, small and medium-sized enterprises. 


4. Providers of hosting services and providers of interpersonal communications services shall 
clearly describe in their terms and conditions the mitigation measures that they have taken. 
That description shall not include information that may reduce the effectiveness of the 
mitigation measures. 


10 


PCY comment: the PCY notes that the age verification and age assessment measures evolve 
rapidly and that therefore it seems advisable to use a formulation that keeps the legislation 
future proof and technology neutral. To complement the Article, a recital could be included as 


follows: “Age verification and age assessment measures taken under this Regulation should 
reserve privacy, including by being in compliance with Regulation (EU) 2016/679. Those 


measures should also take into account the best interest of the child, including the protection 
of their personal data, be effective, proportionate and accurate. The obligation to ensure data 
protection by design and default is of particular importance to protect the personal data of 
children while ensuring a safe online environment for children. The age verification and age 
assessment measures should also be non-discriminatory and accessible.” 


Ee eae SE en The CY pescides arecnnls 
issues-thatmicht be addressed +n this context 
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a: The Commission, in cooperation with Coordinating Authorities and the EU Centre and 
after having conducted a public consultation, may issue guidelines on the application of 
paragraphs 1, 2, 3 and 4, having due regard in particular to relevant technological 
developments and in the manners in which the services covered by those provisions are 
offered and used. 


Article 5 
Risk reporting 


1. Providers of hosting services and providers of interpersonal communications services shall 
transmit, by three months from the date referred to in Article 3(4), to the Coordinating 
Authority of establishment a report specifying the following: 


(a) the premise for the risk assessment pursuant to Article 3(2), the process and the 
results of the risk assessment conducted or updated pursuant to Article 3, including 
the assessment of any potential remaining risk referred to in Article 3(5); 


(b) any mitigation measures taken pursuant to Article 4 and the results thereof 


including the effectiveness of these measures and how they comply with the 
requirements of Article 4(2); 


(ba) any other mitigation measures implemented before carrying out the risk 
assessment and, when available, complementary informations about the 
effectiveness of these measures; 


of Article 42); 


(c) where potential remaining risk as referred to in Article 3(5) is identified, any 
available information relevant for identifying as precisely as possible the parts 
or components of the service, or the specific users or groups of users, in respect 
of which the potential remaining risk arises and-the-planned_further_measures 

ae his-risk. 


When—made—available, tThis report sheuld shall include available statistical 
information to support and illustrate the development and effectiveness of mitigation 
measures. 


- Within three months after receiving the report, the Coordinating Authority of establishment 
shall assess it and determine, on that basis and taking into account any other relevant 
information available to it, whether the risk assessment has been preperly diligently 
carried out or updated and the mitigation measures have been taken in accordance with the 
requirements of Articles 3 and 4 and evaluate the level of the remaining risk. 


The Coordinating Authority of establishment may request the EU Centre to assist in 
evaluating the mitigation measures taken by the provider as well as evaluating the 
level of the remaining risk. 
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I> 


Where necessary for that assessment, that Coordinating Authority may require further 
information from the provider, within a reasonable time period set by that Coordinating 
Authority. That time period shall not be longer than two weeks. 


The time period referred to in the-first subparagraph paragraph 2 of thisArtiele shall be 
suspended until that additional information is provided. 


Withoul-prejudicejo-Ariicles cm RT RRR RRRTEEREERT 2 
Fence ns i review Fert sae a as 
figable- die Gauead 


HaHa eastes et peso ble tie petted setba tht 
Coordinating Authority: That tame period shall nctte longer thas one mone The 


a Providers shall, when transmitting the report to the Coordinating Authority of 
establishment in accordance with paragraph 1, transmit the report also to the EU Centre. 

6. Providers shall, upon request, transmit the report to the providers of software application 
stores, insofar as necessary for the assessment referred to in Article 6(2). Where necessary, 
they may remove confidential information from the reports. 
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Article 5a 1! 


Adjusted or additional risk assessment or risk mitigation measures 


1. Without prejudice to Articles 27 to 29, where on the basis of its assessment referred to 
in Article 5(2), the Coordinating Authority of establishment determines that the 
requirements of Articles 3 and 4 have not been met, it shall require the provider of 
hosting services or the provider of interpersonal communications services to carry 
out one or several of the following actions, as appropriate: 


(a) to re-conduct or update the risk assessment in accordance with Article 3; 

(b) to implement, review, modify, discontinue or expand some or all of the risk 
mitigation measures taken in accordance with Article 4; 

(c) to introduce additional risk mitigation measures in accordance with Article 4. 


2. The provider shall inform the Coordinating Authority of the steps taken to ensure 
compliance with the measures required pursuant to paragraph 1 within a time period 
set by the Coordinating Authority. That time period shall be reasonable, taking into 
account the complexity of the required measures. 


‘ PCY comment: the following recital could be included: “In the interest of ensuring 


effective oversight and compliance, and given the importance of ensuring that all 
possible risk mitigation measures have been taken in accordance with this Regulation 
prior to the issuance of any detection order, the Coordinating Authorities should be 
granted specific powers to require providers of hosting services or providers of 
interpersonal communications services to adjust their risk assessment or mitigation 
measures so as to ensure compliance with the relevant requirements of this Regulation. 
Those specific powers should leave the Coordinating Authorities’ general investigatory 
and enforcement powers under this Regulation unaffected. Therefore, imposing such a 
requirement regarding the further risk assessment or mitigation measures could be 
combined, where appropriate, with other investigatory or enforcement measures, such 
as imposing a periodic penalty payment to ensure compliance with that requirement or 
imposing a fine for failure to comply with this Regulation.” 
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Article 5b!” 


Sign of compliance 


Where both of the following conditions have been met, the Coordinating Authority of 
establishment shall authorise _a_provider_of hosting services or a provider of 
interpersonal telecommunications services, upon its reasoned request, to publicly 
display a distinctive sign of compliance as_a clear visual representation to_users 
indicating that the service concerned meets those conditions: 

(a) the Coordinating Authority considers that the provider has satisfactorily carried 
out the risk assessment in accordance with Article 3 and has taken all reasonable 
and _ necessary risk mitigation measures in accordance with Article 4, including 
where applicable pursuant to Article 5a; 


(b) the Coordinating Authority considers that there is no need to initiate the process 
for the issuance of a detection order in accordance with Article 7, having regard 
in particular to the nature and extent of any remaining risk referred to in Article 
5(2) and the conditions set out in Article 7(4). 


2. The sign shall only be displayed with the authorisation referred to in paragraph 1. It 
shall not be displayed where the authorisation has been suspended or withdrawn in 
accordance with paragraph 4. 


3. Providers authorised in accordance with paragraph 1 shall, for _as long as the 
authorisation is not withdrawn or suspended, do both of the following: 


(a) prominently display the sign on the service concerned; 

(b) include, in a clear and easily understandable manner, the necessary explanations 
regarding the sign in their terms and conditions, including about the conditions 
met to be authorised to display the sign and the fact that the authorisation does 
not mean that the risk of online child sexual abuse is completely eliminated. 


4. The Coordinating Authority that issued an authorisation in accordance with paragraph 
1 shall regularly review whether the conditions set out in that paragraph continue to be 
met, taking due account of the risk reporting in accordance with Article 5 and all other 
relevant information. Where necessary to that aim, it may require the provider 
concerned to do one or both of the following: 


a) conduct or update a risk assessment, take the necessary risk mitigation measures 


b 


and report thereon in accordance with Articles 3, 4 and 5 respectively; 


) provide any other relevant information. 


12 


PCY comment: drafting suggestions building on the text proposed by one delegation, taking 


into account the comments provided by other delegations during the LEWP meeting of 13 
June, notably to ensure that this label is not seen as a complete lack of risk and that it comes 
with additional oversight requirements. 
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The Coordinating Authority shall immediately suspend the authorisation where it has 
reasonable doubts about the provider’s continued compliance with the conditions of 
paragraph 1. During the suspension, it shall review such compliance, including by 
requiring the provision of information pursuant to the first subparagraph where 
appropriate. It shall conclude the review, without undue delay, either by terminating 
the suspension or by withdrawing the authorisation. 


The Coordinating Authority shall withdraw the authorisation where it considers that 
the provider no longer meets the conditions of paragraph 1, after having informed the 
provider of its intention to withdraw the authorisation and the reasons for that 
intention and having given the provider an opportunity to comment thereon within a 
reasonable time period. It shall also withdraw the authorisation upon request of the 
provider. 


5. Coordinating Authorities shall immediately inform the provider concerned and the EU 
Centre about each authorisation granted, suspended or withdrawn in accordance with 


paragraphs 1 and 4. The EU Centre shall maintain a publicly available registry of that 
information. 


6. The issuance of an authorisation in accordance with paragraph 1 shall not affect the 
Coordinating Authority’s possibility to initiate the process for the issuance of a 


detection order in accordance with Article 7. 


7. The Commission shall be empowered to adopt delegated acts in accordance with Article 
86 in order to supplement this Regulation with the necessary detailed rules on requests 
for authorisation to display the sign, on the issuance, suspension and withdrawal of the 
authorisation, on the design of the sign, on the display of the sign and the provision of 
information to users relating thereto, on the regular review of continued compliance 
with the conditions and on the registry of information. 


Article 6 
Obligations for software application stores 
1. Providers of software application stores shall: 
(a) make reasonable efforts to assess, where possible together with the providers of 
software applications, whether each service offered through the software applications 


that they intermediate presents a risk of being used for the purpose of the solicitation 
of children; 


(b) take reasonable measures to prevent child users from accessing the software 
applications in relation to which they have identified a significant risk of use of the 
service concerned for the purpose of the solicitation of children; 
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(c) take the necessary age verification and age assessment measures!’ to reliably identify 
child users on their services, enabling them to take the measures referred to in point 


(b). 


2 In assessing the risk referred to in paragraph 1, the provider shall take into account all the 
available information, including the results of the risk assessment conducted or updated 
pursuant to Article 3. 


3: Providers of software application stores shall make publicly available information 
describing the process and criteria used to assess the risk and describing the measures 
referred to in paragraph 1. That description shall not include information that may reduce 
the effectiveness ofthe-assessment of those measures. 


4. The Commission, in cooperation with Coordinating Authorities and the EU Centre and 
after having conducted a public consultation, may issue guidelines on the application of 
paragraphs 1, 2 and 3, having due regard in particular to relevant technological 
developments and to the manners in which the services covered by those provisions are 
offered and used. 


Artiele-6a"* 
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4. Fhe-EU—Centre-shalt intai i i i i i 


5. The C inati j j eertification—and.—when 


Section 2 
Detection obligations 


Article 7 
Issuance of detection orders 


1. The Coordinating Authority of establishment shall have the power to request the competent 


judicial authority of the Member State that designated it or—another independent 
administrative—authority—of that Member-State to issue a detection order requiring a 


provider of hosting services or a provider of interpersonal communications services under 
the jurisdiction of that Member State to take the measures specified in Article 10 to detect 
online child sexual abuse on a specific service. 


2. The Coordinating Authority of establishment shall, before requesting the issuance of a 
detection order, carry out the investigations and assessments necessary to determine 
whether the conditions of paragraph 4 have been met. 


To that end, it may;-where—apprepriate, require the provider to submit the necessary 
information, additional to the report and the further information referred to in Article 5(1) 
and (3), respectively, within a reasonable time period set by that Coordinating Authority, 
or request the EU Centre, another public authority or relevant experts or entities to provide 
the necessary additional information. 


ae Where the Coordinating Authority of establishment takes the preliminary view that the 
conditions of paragraph 4 have been met, it shall: 


(a) establish a draft request for the issuance of a detection order, specifying the main 
elements of the content of the detection order it intends to request and the reasons 
including the necessity for requesting it; 


(b) submit the draft request to the provider and the EU Centre; 
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(c) afford the provider an opportunity to comment on the draft request, within a 
reasonable time period set by that Coordinating Authority; 


(d) invite the EU Centre to provide its opinion on the draft request, within a time period 
of four weeks from the date of receiving the draft request. 


Where, having regard to the comments of the provider and the opinion of the EU Centre, 
that Coordinating Authority continues to be of the view that the conditions of paragraph 4 
have met, it shall re-submit the draft request, adjusted where appropriate, to the provider. 
In that case, the provider shall do all of the following, within a reasonable time period set 
by that Coordinating Authority: 


(a) draft an implementation plan setting out the measures it envisages taking to execute 
the intended detection order, including detailed information regarding the envisaged 
technologies and safeguards; 


(b) where the draft implementation plan concerns an intended detection order concerning 
the solicitation of children other than the renewal of a previously issued detection 
order without any substantive changes, conduct a data protection impact assessment 
and a prior consultation procedure as referred to in Articles 35 and 36 of Regulation 
(EU) 2016/679, respectively, in relation to the measures set out in the 
implementation plan; 


(c) where point (b) applies, or where the conditions of Articles 35 and 36 of Regulation 
(EU) 2016/679 are met, adjust the draft implementation plan, where necessary in 
view of the outcome of the data protection impact assessment and in order to take 
into account the opinion of the data protection authority provided in response to the 
prior consultation; 


(d) submit to that Coordinating Authority the implementation plan, where applicable 
attaching the opinion of the competent data protection authority and specifying how 
the implementation plan has been adjusted in view of the outcome of the data 
protection impact assessment and of that opinion. 


Where, having regard to the implementation plan of the provider and the received 
opinions of the data protection authority, that Coordinating Authority continues to be of the 
view that the conditions of paragraph 4 have met, it shall submit the request for the 
issuance of the detection order, adjusted where appropriate, to the competent judicial 
authority orindependent administrative authority. It shall attach the implementation plan of 
the provider and the opinions of the EU Centre and the data protection authority to that 
request and, when appropriate, the reasons for diverging from the opinions received. 
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4. The Coordinating Authority of establishment shall request the issuance of the detection 


order, and the competent judicial authority er+ndependent-administratrve-autherty may 


shal issue the detection order where it considers that the following conditions are met: 


(a) 


(b) 


there is evidence of a significant_and present or foreseeable risk!> of the service 
being used for the purpose of online child sexual abuse, within the meaning of 
paragraphs 5, 6 and 7, as applicable; 


the reasons for issuing the detection order outweigh negative consequences for the 
rights and legitimate interests of all parties affected, having regard in particular to the 
need to ensure a fair balance between the fundamental rights of those parties. 


When assessing whether the conditions of the first subparagraph have been met, account 
shall be taken of all relevant facts and circumstances of the case at hand, in particular: 


(a) 


(b) 


(c) 


(d) 


the risk assessment conducted or updated and any mitigation measures taken by the 
provider pursuant to Articles 3 and 4, including any mitigation measures introduced, 
reviewed, discontinued or expanded pursuant to Article 5a 544) where applicable; 


any additional information obtained pursuant to paragraph 2 or any other relevant 
information available to it, in particular regarding the use, design and operation of 
the service, regarding the provider’s financial and technological capabilities and size 
and regarding the potential consequences of the measures to be taken to execute the 
detection order for all other parties affected; 


the views and the implementation plan of the provider submitted in accordance with 
paragraph 3; 


the opinions of the EU Centre and of the data protection authority submitted in 
accordance with paragraph 3. 


As regards the second subparagraph, point (d), where that Coordinating Authority 
substantially deviates from the opinions received of the EU Centre, it shall inform the EU 
Centre and the Commission thereof, specifying the points at which it deviated and the main 
reasons for the deviation. 


15 


PCY comment: the PCY notes that delegations perceive the term “significant risk” to be too 


vague and should be replaced by a more precise wording. 
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De As regards detection orders concerning the dissemination of known child sexual abuse 
material, the significant risk referred to in paragraph 4, first subparagraph, point (a), shall 
be deemed to exist where the following conditions are met: 


(a) 


(b) 


itistikely, there are objective indications despite any mitigation measures that the 


provider may have has taken or will take, thatthereis-a-genuine-and present-or 
fereseeable-risk that the service is or will be used, to an appreciable extent!® for the 


dissemination of known child sexual abuse material; 


there is evidence of the service, or of a comparable service if the service has not yet 
been offered in the Union at the date of the request for the issuance of the detection 
order, having been used in the past 12 months and to an appreciable extent for the 
dissemination of known child sexual abuse material. 


6. As regards detection orders concerning the dissemination of new child sexual abuse 
material, the significant risk referred to in paragraph 4, first subparagraph, point (a), shall 
be deemed to exist where the following conditions are met: 


(a) 


(b) 


(c) 


itis tikely!7, there are objective indications despite any mitigation measures that 


the provider may have has taken or will take, that there is-a-genuine-and present 
or-foreseeable risk that the service is or will be used, to an appreciable extent for 


the dissemination of new child sexual abuse material; 


there is evidence of the service, or of a comparable service if the service has not yet 
been offered in the Union at the date of the request for the issuance of the detection 
order, having been used in the past 12 months and to an appreciable extent, for the 
dissemination of new child sexual abuse material; 


for services other than those enabling the live transmission of pornographic 
performances as defined in Article 2, point (e), of Directive 201 1/93/EU: 


(1) a detection order concerning the dissemination of known child sexual abuse 
material has been issued in respect of the service; 


(2) the provider submitted a significant number of reports concerning known child 
sexual abuse material, detected through the measures taken to execute the 
detection order referred to in point (1), pursuant to Article 12. 
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PCY comment: the PCY notes that delegations perceive this term to be too vague and should 


be replaced by a more precise wording. It has been mentioned that a more precise wording 
could include a reference to quantitative facts, for example that the Coordinating Authority 
needs to demonstrate a certain number of transmissions of child sexual abuse material or 
messages constituting solicitation during a set time frame. 
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ce As regards detection orders concerning the solicitation of children, the significant risk 
referred to in paragraph 4, first subparagraph, point (a), shall be deemed to exist where the 
following conditions are met: 


(a) the provider qualifies as a provider of interpersonal communications services 
excluding such services consisting of real-time audio-conmunications:” 

(b) i#istikely there are objective indications despite any mitigation measures that the 
provider may have has taken or will take, 


thatthe ene presen oF 
fereseeablerisk that the service is used_or will be, to an appreciable extent for the 
solicitation of children; 


(c) there is evidence of the service, or of a comparable service if the service has not yet 
been offered in the Union at the date of the request for the issuance of the detection 
order, having been used in the past 12 months and to an appreciable extent, for the 
solicitation of children. 


The detection orders concerning the solicitation of children shall apply only to 
interpersonal communications where one of the users is a child user!?-and shall not apply 
to calls. 


8. The Coordinating Authority of establishment when requesting the issuance of detection 
orders, and the competent judicial er+ndependentadministrative-autherity when issuing the 
detection order, shall target and specify it in such a manner that the negative consequences 
referred to in paragraph 4, first subparagraph, point (b), remain limited to what is strictly 
necessary to effectively address the significant risk referred to in point (a) thereof. 


To that aim, they shall take into account all relevant parameters, including the availability 
of sufficiently reliable detection technologies in that they limit to the maximum extent 
possible the rate of errors regarding the detection and their suitability and effectiveness for 
achieving the objectives of this Regulation, as well as the impact of the measures on the 
rights of the users affected, and require the taking of the least intrusive measures, in 
accordance with Article 10, from among several equally effective measures. 


18 PCY comment: The Presidency suggests complementing recital 21 with the following 


wording: “For those reasons, additional limits should be set in respect of detection orders 
concerning the solicitation of children, such as: the exclusion of calls i+mterpersenal 
HHH AHOP 4 Pett : A as, that is, connections 
established by means of a_publicly available aierpeaona communications service 
allowing two-way voice audio communications that allow the persons -coneemed to interact 
with-each-other-with no-oFr ne de and that do-netinvelve-any ree as 
of the-transmission_precess. Other interpersonal communications services, including those 
involving audio voice communications net+n-+realtime-but through recorded and transmitted 
audio voice communications, should however remain covered and thus be potentially subject 
to such detection orders.” 


PCY comment: The PCY concludes that both the term ‘child’ and ‘child user’ as defined at 
present will cause difficult issues requiring further work. 
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In particular, they shall ensure that: 


(a) where that risk is limited to an identifiable part or component of a service”®, the 
required measures are only applied in respect of that part or component; 


(b) where necessary, in particular to limit such negative consequences, effective and 
proportionate safeguards additional to those listed in Article 10(4), (5) and (6) are 
provided for; 


(c) subject to paragraph 9, the period of application remains limited to what is strictly 
necessary. 


The competent judicial authority erindependent-administrative-authertty shall specify in 


the detection order the period during which it applies, indicating the start date and the end 
date. 


The start date shall be set taking into account the time reasonably required for the provider 
to take the necessary measures to prepare the execution of the detection order. It shall not 
be earlier than three months from the date at which the provider received the detection 
order and not be later than 12 months from that date. 


The period of application of detection orders concerning the dissemination of known or 
new child sexual abuse material shall not exceed 24 months and that of detection orders 
concerning the solicitation of children shall not exceed 12 months. 


Article & 


Additional rules regarding detection orders 


The competent judicial authority er+mdependent-administrative-autherity shall issue the 


detection orders referred to in Article 7 using the template set out in Annex I. Detection 
orders shall include: 


(a) information regarding the measures to be taken to execute the detection order, 
including the indicators to be used and the safeguards to be provided for, including 
the reporting requirements set pursuant to Article 9(3) and, where applicable, any 
additional safeguards as referred to in Article 7(8); 


(b) identification details of the competent judicial authority er—the—mdependent 


administrative—authority issuing the detection order and authentication of the 
detection order by that judicial erindependentadministrative authority; 
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(c) the name of the provider and, where applicable, its legal representative; 


(d) the specific service in respect of which the detection order is issued and, where 
applicable, the part or component of the service affected as referred to in Article 
7(8); 


(e) whether the detection order issued concerns the dissemination of known or new child 
sexual abuse material or the solicitation of children; 


(f) the start date and the end date of the detection order; 


(g) a sufficiently detailed statement of reasons explaining why the detection order is 
issued; 


(h) areference to this Regulation as the legal basis for the detection order; 


(i) the date, time stamp and electronic signature of the judicial er—mdependent 
administrative authority issuing the detection order; 


(j) easily understandable information about the redress available to the addressee of the 
detection order, including information about redress to a court and about the time 
periods applicable to such redress. 


oe The competent judicial authority er+ndependent-administrative—autherity issuing the 


detection order shall address it to the main establishment of the provider or, where 
applicable, to its legal representative designated in accordance with Article 24. 


The detection order shall be transmitted to the provider’s point of contact referred to in 
Article 23(1), to the Coordinating Authority of establishment and to the EU Centre, 
through the system established in accordance with Article 39(2). 


The detection order shall be drafted transmitted in any of the official languages declared 
by the provider pursuant to Article 23(3). 


The order may also be transmitted in any of the official languages of the Member 
State autherity issuing the order, provided that it is accompanied by a translation of 
at least the most important elements necessary for the execution of the order into any 
of the official languages declared by the provider in accordance with article 23(3). 


3. If the provider cannot execute the detection order because it contains manifest errors or 
does not contain sufficient information for its execution, the provider shall, without undue 
delay, inform request—the—necessary—clarification—te the Coordinating Authority of 
establishment, using the template set out in Annex II. That Coordinating Authority shall 
assess the matter and request the competent judicial authority or—independent 
administrative—authority—that issued the detection order the modification or 
revocation of such order, where necessary in the light of the outcome of that 
assessment. 
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4. The Commission shall be empowered to adopt delegated acts in accordance with Article 86 
in order to amend Annexes I and II where necessary to improve the templates in view of 
relevant technological developments or practical experiences gained. 


Article 9 
Redress, information, reporting and modification of detection orders 


1. Providers of hosting services and providers of interpersonal communications services that 
have received a detection order, as well as users affected by the measures taken to execute 
it, shall have a right to effective redress. That right shall include the right to challenge the 
detection order before the courts of the Member State of the competent judicial authority er 


independent administrative-authority that issued the detection order. 


2. When the detection order becomes final, the competent judicial authority erindependent 
administrative-autherity that issued the detection order shall, without undue delay, transmit 
a-copy_thereoHte inform the Coordinating Authority of establishment. The Coordinating 
Authority of establishment shall then, without undue delay, transmit a copy thereof of the 
detection order to all other Coordinating Authorities through the system established in 
accordance with Article 39(2). 


For the purpose of the first subparagraph, a detection order shall become final upon the 
expiry of the time period for appeal where no appeal has been lodged in accordance with 
national law or upon confirmation of the detection order following an appeal. 


3 Where the period of application of the detection order exceeds 12 months, or six months in 
the case of a detection order concerning the solicitation of children, the Coordinating 
Authority of establishment shall require the provider to report to it the necessary 
information on the execution of the detection order at least once, halfway through the 
period of application. 


Those reports shall include a detailed description of the measures taken to execute the 
detection order, including the safeguards provided, and information on the functioning in 
practice of those measures, in particular on their effectiveness in detecting the 
dissemination of known or new child sexual abuse material or the solicitation of children, 
as applicable, and on the consequences of those measures for the rights and legitimate 
interests of all parties affected. 


4. tarespeet_of the detection orden that the-eonipetent ude aathetits—or_ndepencdent 
administrative authority issued at its request, The Coordinating Authority of establishment 
shall, where necessary and in any event following reception of the reports referred to in 
paragraph 3, assess whether any substantial changes to the grounds for issuing the 
detection orders occurred and, in particular, whether the conditions of Article 7(4) continue 
to be met. In that regard, it shall take account of additional mitigation measures that the 
provider may take to address the significant risk identified at the time of the issuance of the 
detection order. 
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That Coordinating Authority shall request to the competent judicial authority er 
independent-administrative—autheritty that issued the detection order the modification or 
revocation of such order, where necessary in the light of the outcome of that assessment. 
The provisions of this Section shall apply to such requests, mutatis mutandis. 


Article 10 
Technologies and safeguards 


Providers of hosting services and providers of interpersonal communications services that 
have received a detection order shall execute it by installing and operating technologies to 
detect the dissemination of known or new child sexual abuse material or the solicitation of 
children, as applicable, using the corresponding indicators provided by the EU Centre in 
accordance with Article 46. 


The provider shall be entitled to acquire, install and operate, free of charge, technologies 
made available by the EU Centre in accordance with Article 50(1), for the sole purpose of 
executing the detection order. The provider shall not be required to use any specific 
technology, including those made available by the EU Centre, as long as the requirements 
set out in this Article are met. The use of the technologies made available by the EU Centre 
shall not affect the responsibility of the provider to comply with those requirements and for 
any decisions it may take in connection to or as a result of the use of the technologies. 


The technologies shall be: 


(a) effective in detecting the dissemination of known or new child sexual abuse material 
or the solicitation of children, as applicable; 


(b) not be able to extract any other information from the relevant communications than 
the information strictly necessary to detect, using the indicators referred to in 
paragraph 1, patterns pointing to the dissemination of known or new child sexual 
abuse material or the solicitation of children, as applicable; 


(c) in accordance with the state of the art in the industry and the least intrusive in terms 
of the impact on the users’ rights to private and family life, including the 
confidentiality of communication, and to protection of personal data; 


(d) sufficiently reliable, in that they limit to the maximum extent possible the rate of 
errors regarding the detection. 
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The provider shall: 


(a) 


(b) 


(c) 


(d) 


(c) 


(f) 


take all the necessary measures to ensure that the technologies and indicators, as well 
as the processing of personal data and other data in connection thereto, are used for 
the sole purpose of detecting the dissemination of known or new child sexual abuse 
material or the solicitation of children, as applicable, insofar as strictly necessary to 
execute the detection orders addressed to them; 


establish effective internal procedures to prevent and, where necessary, detect and 
remedy any misuse of the technologies, indicators and personal data and other data 
referred to in point (a), including unauthorized access to, and unauthorised transfers 
of, such personal data and other data; 


ensure regular human oversight as necessary to ensure that the technologies operate 
in a sufficiently reliable manner and, where necessary, in particular when 
potential errors and potential solicitation of children are detected, human 
intervention; 


establish and operate an accessible, age-appropriate and user-friendly mechanism 
that allows users to submit to it, within a reasonable timeframe, complaints about 
alleged infringements of its obligations under this Section, as well as any decisions 
that the provider may have taken in relation to the use of the technologies, including 
the removal or disabling of access to material provided by users, blocking the users’ 
accounts or suspending or terminating the provision of the service to the users, and 
process such complaints in an objective, effective and timely manner; 


inform the Coordinating Authority, at the latest one month before the start date 
specified in the detection order, on the implementation of the envisaged measures set 
out in the implementation plan referred to in Article 7(3); 


regularly review the functioning of the measures referred to in points (a), (b), (c) and 
(d) of this paragraph and adjust them where necessary to ensure that the requirements 
set out therein are met, as well as document the review process and the outcomes 
thereof and include that information in the report referred to in Article 9(3). 


The provider shall inform users in a clear, prominent and comprehensible way of the 
following: 


(a) 


the fact that it operates autemated technologies (autemated_profiling) to detect 
online child sexual abuse to execute the detection order, the ways in which it 
operates those technologies, meaningful information about the logic involved, and 
the impact on the confidentiality of users’ communications;?! 


PCY comment: the PCY is of the view that this article can be further developed in terms of 


data protection. The PCY wishes to hear the delegations’ views on the changes proposed in 
paragraph 5. 
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(b) the fact that it is required to report potential online child sexual abuse to the EU 
Centre in accordance with Article 12; 


(c) the users’ right of judicial redress referred to in Article 9(1) and their rights to submit 
complaints to the provider through the mechanism referred to in paragraph 4, point 
(d) and to the Coordinating Authority in accordance with Article 34. 


the-users’ ri as-data jects under 


The provider shall not provide information to users that may reduce the effectiveness of the 
measures to execute the detection order. 


Where a provider detects potential online child sexual abuse through the measures taken to 
execute the detection order, it shall inform the users concerned without undue delay, after 
Eurepelerthe national law enforcement authority of a Member State that received the 
report pursuant to Article 48 has confirmed that the information to the users would not 
interfere with activities for the prevention, detection, investigation and prosecution of child 
sexual abuse offences. 


Article 11 


Guidelines regarding detection obligations 


The Commission, in cooperation with the Coordinating Authorities and the EU Centre and after 
having conducted a public consultation, may issue guidelines on the application of Articles 7 to 10, 
having due regard in particular to relevant technological developments and the manners in which 
the services covered by those provisions are offered and used. 


Section 3 
Reporting obligations 
Article 12 
Reporting obligations 


Where a provider of hosting services or a provider of interpersonal communications 
services becomes aware in any manner other than through a removal order issued in 
accordance with this Regulation of any information imdicating that indicate potential 
online child sexual abuse on its services, it shall promptly submit a report thereon to the 
EU Centre in accordance with Article 13. It shall do so through the system established in 
accordance with Article 39(2). 
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De Where the provider submits a report pursuant to paragraph 1, it shall inform the users 
concerned, in accordance with the following sub-paragraphs providing information on 


the main content of the report;-en+he-mannerin—which the-provider has become-awareof 
the-petential chHd sexual abuse-concerned,_onthe folow—up-eivento the report insefaras 


suchmfermation_is—avatlabletetheprovider and on the users possibilities of redress, 


including on the right to submit complaints to the Coordinating Authority in accordance 
with Article 34. 


The provider shall inform the users concerned without undue delay, either after having 
received a communication from the EU Centre indicating that it considers the report to be 
manifestly unfounded as referred to in Article 48(2), or after the expiry of a time period of 
six three months from the date of the report without having received a communication 
from the EU Centre indicating that the information is not to be provided as referred to in 
Article 48(6), point (a), whichever occurs first. The time period of six months refered to 
in this subparagraph shall be extended by up to 6 months where so requested by the 
competent authority referred to in Article 48(6)-peinta. 


Where within the three+menths~ time period referred to in the second subparagraph the 
provider receives such a communication from the EU Centre indicating that the 
information is not to be provided, it shall inform the users concerned, without undue delay, 
after the expiry of the time period set out in that communication. 


3. The provider shall establish and operate an easy to access, accessible, effective, ehild- 
friendly age-appropriate and user-friendly, in particular child-friendly, mechanism that 
allows users to notify flag to the provider information that indicate potential online child 
sexual abuse on its-the service. Those mechanisms shall allow for the submission of 
notices by individuals or entities exclusively by electronic means. 


The mechanisms shall be such as to facilitate the submission of sufficiently precise 
and adequately substantiated notices. To that end, the providers shall take the 
necessary measures, with particular attention to the needs of the child, to enable and 
to facilitate the submission of notices, with a view to receiving: 


(a) the reasons why the user alleges that the material or conversation at issue 
constitutes elaimsthatthe notice contains online child sexual abuse; 


(b) a clear indication of the online location of the alleged online child sexual abuse 
and, where necessary, additionalinformation specific to a service that enables 
the identification of its online location. 


4. The Commission, in cooperation with Coordinating Authorities and the EU Centre 
and after having conducted a public consultation, shall issue guidelines on the 
application of paragraph 3, having due regard in particular to the child's age, 
maturity, views, needs and concerns. 
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Article 13 


Specific requirements for reporting 


1. Providers of hosting services and providers of interpersonal communications services shall 
submit the report referred to in Article 12 using the template set out in Annex III. The 
report shall include: 


(a) 
(b) 
(ba) 


(c) 


(d) 


(c) 


(f) 


(g) 


(h) 


22 
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identification details of the provider and, where applicable, its legal representative; 
the date, time stamp and electronic signature of the provider; 


manner in which the provider became aware of the potential child sexual 
abuse”; 


alt—content data related to the reported potential online child sexual abuse; 
chadian s ee sais 
alt other available data related to the reported potential online child sexual abuse, 


including unique identifiers of the user and metadata” related to media files 
and communications; 


whether the potential online child sexual abuse concerns the dissemination of known 
or new child sexual abuse material or the solicitation of children; 


information concerning the geographic location related to the potential online child 
sexual abuse, such as the Internet Protocol address of upload, with associated date 
and time stamp, and port number; 


information concerning the identity of any user involved in the potential online child 
sexual abuse; 


whether the provider has also reported, or will also report, the information that 
indicate potential online child sexual abuse to a third-country public authority or 
other entity competent to receive such reports ef-athird-country and if so, which 
authority or entity; 


PCY comment: the type of source of the report will be included in Annex III, Chapter II, 
point 8. 
PCY comment: Proposal for a new recital 29a: “Metadata connected to reported potential 


online child sexual abuse is may be useful for investigative purposes and for the purpose to 
identify a suspect of a child sexual abuse offence. For the purpose of this Regulation, the term 
‘metadata’ should be understood as data other than #ex-content data referring to information 
about documents, files or communications. Metadata may include, depending on the case, 
information about the time and place of, and the devices used for, the creation or exchange of 
the documents, files or communications at issue and about any modifications made thereto.” 
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la. 


(1) where the information that indicate potential online child sexual abuse concerns the 
dissemination of known or new child sexual abuse material, whether the provider has 
removed or disabled access to the material, and, where relevant, whether it has 
been done on a voluntary basis; 


(j) | whether the provider considers that the report requires urgent action; 4 
(k) areference to this Regulation as the legal basis for reporting. 


By deviation from paragraph 1, where the information referred to in Article 12(1) 
reasonably justifies the conclusion that there is likely to be an imminent threat to the 
life or safety of a child or when the information indicates ongoing abuse, the report 
referred to in paragraph 1 of this Article shall include: 


(a) in any event, the information referred to in points (a), (b), (f), (j) and (k) of 
paragraph 1 of this Article; 


(b) the information referred to in the other points of paragraph 1 of this Article, 
only insofar as that information is immediately available and the inclusion 
thereof in the report does not delay the submission of the report. 


Where the report referred to in the first subparagaph does not contain all 
information referred to in paragraph 1 of this Article in accordance with point (b) of 
the first subparagraph, the provider of hosting services or of interpersonal 
communications services concerned shall be promptly submit an additional report 
containing all that information, updated or completed where relevant. That 
additional report shall include a reference to the initial report submitted in 
accordance with the first subparagaph and shall indicate which information has been 
updated or completed. 


The Commission shall be empowered to adopt delegated acts in accordance with Article 86 
in order to amend Annex III to improve the template where necessary in view of relevant 
technological developments or practical experiences gained. 


24 


PCY comment: In the template of Annex III, section 2, point 1, we could add the reasons for 


the urgency. It has also been proposed to provide a definition of urgency, for example by using the 
recitals of the TCO and DSA Regulations. The following recital could be added: “There should be 


an expedited reporting procedure when the information reported by the provider reasonably 
justifies the conclusion that there is likely to be an imminent threat to the life or safety of a 
child or when the information indicates ongoing abuse. The expedited reporting procedure 
should limit the information required to be reported to the most necessary items of 
information and include the rest of the information required in the standard reporting 
procedure only if immediately available. The expedited reporting procedure should also 
include an expedited processing by the EU Centre. In addition to the cases that require 
expedited reporting, the provider should indicate in the report other situations that require 
urgent action but not expedited reporting, such as situations where the provider is aware of 
an ongoing investigation and the information reported by the provider reasonably justifies the 
conclusion that such information could be beneficial to that investigation.” 
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Member State in-which the offence suspected t-have taken place tobe taking place 


poses Pac docated: BE tlie Menihor Statoivhere the Hietim-6f the-wuspected offence 
Fositos-or ds tocatedk 


Section 4 
Removal obligations 


Article 14 


Removal orders 


Te 


ie okt Mle as 
aes, Sea, eee eee pe ore ee eer 


identified as-cauetMaIOHId socucl buse-matorial 


25 Wording copied from Art. 14(5) of the TCO Regulation. 
26 Wording copied from Art. 18(2) of the DSA. 
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ae 


la. 


27 


28 


The competent authority of each Member State efestablishment shall have the power 
to issue a removal order in-aceordance-with relevant national requirements, 
requiring a provider of hosting services to remove or disable access in all Member 
States of one or more specific and-publiclyavailable items of material disseminated-te 
the-publie that, after a diligent assessment, the Coordinating Authority erthe courts oF 
ether ndependent administrative authorities referred tein Article 3644 is identified as 
constituting child sexual abuse material. 


By deviation from the-first subparagraph 1, and without causing undue delays in the 
process of issuance of those orders, Member States may decide that such orders can 
only be issued by a judicial authority at-the-request—of the-competent_authority. 
Where a Member State makes use of this possibility, it shall inform the Commission 
thereof and maintain this information updated. The Commission shall make the 
information received publicly available and maintain this information updated’. 


The provider shall execute the removal order as soon as possible and in any event within 
24 4 hours of receipt thereof. The provider shall take the necessary measures to ensure 
that it is capable to reinstate the material or access thereto in accordance with Article 
15(1a). 


PCY comment: this text could be included as a recital: “(31a) The rules of this Regulation 
should not be understood as affecting the relevant national requirements providing, in 
accordance with Union law, procedural safeguards regarding the issuing of removal, 
blocking or delisting orders, such as the control of the conformity with the applicable legal 
requirements of these orders by an independent authority.” 

PCY comment: This text will be accompanied by this recital: “In order to allow Member 
States to organise the process of issuance of removal, blocking or delisting orders in a manner 
compatible with their respective constitutional requirements and to enhance prior judicial 
control where deemed appropriate, they should have the possibility to require their respective 
competent authorities to request the competent judicial authority of the Member State 
concerned to issue some or all of those three types of orders under this Regulation. That 
possibility to derogate should however only concern the question which authority issues the 
orders. Accordingly, when a Member State makes use of that possibility, the competent 
authority concerned should remain responsible for assessing the need for the order at stake 
and for complying with all of the procedural requirements of this Regulation related to its 
preparation and follow-up. In that case, whilst it is for the competent judicial authority to 
conduct an additional verification of whether the conditions of this Regulation for issuing the 
order in question have been met, those conditions themselves should remain unaltered and be 
applied consistently across the Union. In the interest of effectiveness, that possibility should 
be subject to the Member State concerned taking all reasonable measures to ensure that the 
issuance of the orders by their judicial authorities does not lead to any undue delays. In 
addition, in the interest of transparency and legal certainty, it should be ensured that the 
necessary information regarding the use of the possibility is publicly available.” 
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A removal order shall be issued using the template set out in Annex IV. Removal orders 
shall include: 


(a) identification details of the cempetent—udicial_or—ndependent—administrative 
authority issuing the removal order and authentication of the removal order by that 
authority; 

(b) the name of the provider and, where applicable, of its legal representative; 

(c) the specific service in respect of fer which the removal order is issued; 

(d) a sufficiently detailed statement of reasons explaining why the removal order is 
issued-and 4n-particular-whythe- material constitutes chid sexual abuse material 

(da) where applicable, a statement of reasons explaining why the order is issued to a 
service provider that does not have its main establishment or legal 
representative in the Member State of the issuing authority accerdingte—the 

idedtorinArtielelta: 

(ce) afexactuniferm+resourcetocaterand where necessary, addtional-clear information 
fortheidentification_of enabling the provider to identify and locate the child 
sexual abuse material; 

(f) where applicable, the information about non-disclosure during a specified time 
period, in accordance with Article 15(4), point (c); 

(fa) the information necessary for the application, where relevant, of paragraphs 5, 
6 and 7-reperting requirements pursuant te peint7; 

(g) areference to this Regulation as the legal basis for the removal order; 

(h) the date, time stamp and electronic signature of the }idictal-er—independent 
administrative-competent authority issuing the removal order; 

(1) easily understandable information about the redress available to the addressee of the 
removal order, including information about redress to a court and about the time 
periods applicable to such redress. 

4. The } authority issuing the removal 
order shall address it to the main establishment of the provider or, where applicable, to its 

legal representative designated in accordance with Article 24. 
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it-shal-transmit The removal order shall be transmitted to the the provider’s point of 
contact referred to in Article 23(1) by electronic means capable of producing a written 
record under conditions that allow to establish the authentication of the sender, including 
the accuracy of the date and the time of sending and receipt of the order, to the 
Coordinating Authority of in the Member State whose authority issued the order im 
which the-order-was-issued of-establishment and to the EU Centre, through the system 
established in accordance with Article 39(2). 


It shall draft transmit the removal order in any of the official languages declared by the 
provider pursuant to Article 23(3). 


The order may also be transmitted in any of the official languages of the Member 
State issuing the order, provided that it is accompanied by a translation of at least the 
most important elements necessary for the execution of the order into any of the 
official languages declared by the provider in accordance with article 23(3). 


If the provider cannot execute the removal order on grounds of force majeure or de facto 
impossibility not attributable to it, including for objectively justifiable technical or 
operational reasons, it shall, without undue delay, inform the authority issuing the order 
efestablishment of those grounds, using the template set out in Annex V. 


The time period set out in paragraph 24 shall start to run as soon as the reasons referred to 
in the first subparagraph have ceased to exist. 


If the provider cannot execute the removal order because it contains manifest errors or does 
not contain sufficient information for its execution, it shall, without undue delay, request 
the necessary clarification te from the authority issuing the order efestablishment, using 
the template set out in Annex V. 


The time period set out in paragraph 24 shall start to run as soon as the provider has 
received the necessary clarification. 


The provider shall, without undue delay and using the template set out in Annex VI, 
inform the issuing authority issuing the order, Coordinating Authorityof establishment 
andthe EU Centre of the measures taken to execute the removal order, indicating, in 
particular, whether the provider removed the child sexual abuse material or disabled access 
thereto in all Member States and the date and time thereof. 


The Commission shall be empowered to adopt delegated acts in accordance with Article 86 
in order to amend Annexes IV, V and VI where necessary to improve the templates in view 
of relevant technological developments or practical experiences gained. 
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Article 14a 


Procedure Request for cross-border removal orders” 


1. Competentauthorities ota Member Ste where the hosting service provider does et 


Subject to Article 14, where the hosting service provider does not have its main 
establishment or legal representative in the Member State of the authority that issued 
the removal order, that authority shall, simultaneously to issuing the order to the 
hosting service provider, transmit, ifnecessary through the Coordinating Authority, 
a copy of the removal order to the Coordinating Authority of the Member State 
where the hosting service provider has its main establishment or where its legal 
representative resides or is established. If the receiving Coordinating Authority is not 
the competent authority, it shall transmit the order to the competent authority for the 
purpose of the procedure of this Article. 


29 ~~ PCY comment: 


1) The PCY concludes that the previous proposal did not meet the approval of delegations. 
The present proposal replicates the TCO model, which is already in place, and which has 
already been agreed by Member States. 


2) In addition, the PCY concludes that this specific procedure allowing competent authorities 
to issue removal orders directly to hosting services in another Member State has been the 
subject of difficult discussions due to inter alia the complexity of issues relating to cross- 
border jurisdiction. A way forward that may therefore still be considered is to abandon the 
cross-border procedure completely. 
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Where a hosting service provider receives a removal order as referred to in this 
Article, it shall take the measures provided for in Article 14 and take the necessary 
measures to be able to reinstate the content or access thereto, in accordance with 
paragraph 6 of this Article. 


The competent authority of the Member State where the hosting service provider has 
its main establishment or where its legal representative resides or is established may, 
on its own initiative, within 72 hours of receiving the copy of the removal order in 
accordance with paragraph 1, scrutinise the removal order to determine whether it 
seriously or manifestly infringes this Regulation or the fundamental rights and 
freedoms guaranteed by the Charter. 


Where it finds an infringement, it shall, within the same period, adopt a reasoned 
decision to that effect. 


4. The competent authority shall, before adopting a decision pursuant to the second 
subparagraph of paragraph 3, inform the competent authority that issued the 
removal order of its intention to adopt the decision and of its reasons for doing so. 


5. Where the competent authority adopts a reasoned decision in accordance with 
paragraph 3 of this Article, it shall, without delay, transmit that decision, if necessary 
through the Coordinating Authority, to the authority that issued the removal order, 
the hosting service provider and the EU Centre. 


Where the decision finds an infringement pursuant to paragraph 3 of this Article, the 
removal order shall cease to have legal effects. 


6. Upon receiving a decision finding an infringement communicated in accordance with 
paragraph 5, the hosting service provider concerned shall without undue delay 


reinstate the content or access thereto, without prejudice to the possibility to enforce 
its terms and conditions in accordance with Union and national law. 
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Article 15 
Redress and provision of information 


1. Providers of hosting services that have received a removal order issued in accordance with 
Article 14, as well as the users who provided the material, shall have the right to an 
effective redress. That right shall include the right to challenge such a removal order before 


the courts of the Member State of the competent judicial _autherity—orindependent 
administrative authority that issued the removal order*?. 


la. If the order is repealed reversed as a result of a redress procedure, the provider shall 
without undue delay reinstate the material or access thereto, without prejudice to the 
possibility to enforce its terms and conditions in accordance with Union and national 
law*!. 


2 When the removal order becomes final, the 

administrative authority that issued the removal order shall, without undue delay, transmit 
a copy thereof and copies of the information it has received pursuant to Article 14(5) 
to (7) to the Coordinating Authority of the Member State of the authority issuing the 
removal order ef-establishment. Thate Coordinating Authority ef-establishment shall 
then, without undue delay, transmit a—cepy copies thereof to all other Coordinating 
Authorities and the EU Centre through the system established in accordance with Article 
39(2). 


For the purpose of the first subparagraph, a removal order shall become final upon the 
expiry of the time period for appeal where no appeal has been lodged in accordance with 
national law or upon confirmation of the removal order following an appeal. 


3. Where a provider removes or disables access to child sexual abuse material pursuant to a 
removal order issued in accordance with Article 14, it shall without undue delay, inform 
the user who provided the material of the following: 


(a) the fact that it removed the material or disabled access thereto; 


(b) the reasons for the removal or disabling, providing a copy of the removal order upon 
the user’s request; 


(c) the user’s right to judicial redress referred to in paragraph | and the user’s right to 
submit complaints to the Coordinating Authority in accordance with Article 34. 


3a. The provider shall establish and operate an accessible, age-appropriate and user- 
friendly mechanism that allows users to submit to it complaints about alleged 
infringements of its obligations under this Section. It shall process such complaints in 
an objective, effective and timely manner. 


30 PCY comment: the PCY is of the view that there might be a need to clarify that the court 
receiving a challenge should be a court other than the issuing court. 
31 Wording copied from Art. 4(7) of the TCO Regulation. 
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4. ie! issuing sutherity ee mey decide redress peer 


a ates Ravine sonal’ if necessary with Slevant ble ae 
that the provider is not to disclose any information regarding the removal of or disabling of 
access to the child sexual abuse material, where and to the extent necessary to avoid 
interfering with activities for the prevention, detection, investigation and prosecution of 
child sexual abuse or related criminal offences. 


In such a case: 


(a) the #udictal-autheritorindependent-administratyve—authority issuing the removal 


order shall inform the provider of its decision specifying the applicable time 
period that shall be setthe+time-peried not longer than necessary and not exceeding 
twelve six-weeks, during which the provider is not to disclose such information; 


(b) the obligations set out in paragraph 3 shall not apply during that time period; 


(c} that judicial_autherity_or_independent_administrative—authority_shall_inform the 


The issuing That judicial authorityorindependent-administrative authority issuing the 
removal order may decide to extend the time period referred to in the second 


subparagraph, point (a), by a further time period of maximum six weeks, where and to the 
extent the non-disclosure continues to be necessary. In that case, the issuing that+udicial 
authority_or independent administrative authority shall inform the provider of its decision, 


specifying the applicable time period. Article +4)shal -apphte that decision. 


Section 5 
Blocking obligations 


Article 16 
Blocking orders 
1. The competent authority of establishment Coordimatine Autherty-of establishment shall 


ae a” “ to eas ee the ee scene sere of ae ponte State—that 
: to issue a 


bition order, in accordance with relevant national Ponulreiedia requiring a provider 
of internet access services under the jurisdiction of that Member State to take reasonable 
measures to prevent: users from accesses known child sexual abuse Sanen eens ene | 


Ws ARE ONES Seine (aid presided 5 tne EU 
Centre. The competent authorities may make use of the list of uniform resource 
locators included in the database of indicators, in accordance with Article 44(2), point 
(b) and provided by the EU Centre. 
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la. 


By deviation from the first subparagraph, and without causing undue delays in the 
process of issuance of those orders, Member States may decide that such orders can 
only be issued by a judicial authority at the request of the competent authority. 
Where a Member State makes use of this possibility, it shall inform the Commission 
thereof and maintain this information updated. The Commission shall make the 
information received publicly available and maintain this information updated. 


The provider shall execute the blocking order as soon as possible and in any event 
within a reasonable time period set by the issuing authority one-week—of-eceipt 
thereof. The provider shall take the necessary measures to ensure that it is capable of 
reinstating access in accordance with Article 18(1a). 


bietine ee “earry. eut all usuneaions ae assessments necessary. te eee 
ahetherthe conditiei of paracraph thease been ek 
Fethatend it shal where-approepriate: 


locos onthe Hs eared to in parapraph [the conditions of Ace 30 point 


Gonire-that the lieve complele: accurate aff aee ate: 


srotiders Gndncial andi MMI Deal cavabiiies andcize: 
(c) niet ey EU—GCentre—te a a Hecate i ala Te ah 
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4. cai saci cid cane shall request the issuance of the blocking 
blocking idee shall le issued: hele Heeoasiders that the following conditions are met: 


(a) other equally effective and less intrusive measures than blocking cannot be 
taken to prevent access to child sexual abuse material or if it is likely that such 
measure will fail; aad is-e¥ seenee atthe sere ee ae oon ee ae the past 


Gane TERE RAR 


(b) the blocking order is necessary to prevent the dissemination of the-child sexual abuse 
material te-asers in the Union, having regard in -particulartethe- quantity and nature 


efthe- material to the need to protect the rights of the victims andthe-existence and 
implementation bythe provider ofa poheyto address the tisk of such dissemination; 


(d) the reasons for issuing the blocking order outweigh negative consequences for the 
rights and legitimate interests of all parties affected, having regard in particular to the 
need to ensure a fair balance between the fundamental rights of those parties, 
including the exercise of the users’ freedom of expression and information and the 
provider’s freedom to conduct a business. 


When assessing whether the conditions of the first subparagraph have been met, account 
shall be taken of all relevant facts and circumstances of the case at hand;inehidine any 
+Htesmiation-ebtited satsuat te pach ae the es of the pros tte sb ted 3 
accordance with _ paragraph 3. 


De FheCoordinatine Autherityof establishment when requestine the issuance_of blocking 
orders he competent ictera erindependent id tistics ator pe ttt the 
A blocking order; shall: 


(a) where—necessary, specify effective—and—prepertionate limits and—safeguards 
necessary to ensure that a blocking order is targeted and that any negative 
consequences referred to in paragraph 4, point (d), remain limited to what is strictly 
necessary; 


(b) subject to paragraph 6, ensure that the period of application remains limited to what 
is strictly necessary. 


32, PCY comment: examples of “less intrusive measures” can for instance be a failed notice, a 


removal order that cannot be executed or a removal order towards a so-called “bulletproof 
service provider”. This could be clarified in a recital. 
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6. The issuing Cooerdinating—authority shall specify in the blocking order the period during 
which it applies, indicating the start date and the end date. 


The period of application of blocking orders shall not exceed five years. 


ve in-respect_of the_blockine—orders—that the-competent judicial autherity_or independent 
administrative-autherity issued_at its request +The Coordinating Authority or the issuing 
authority shall, where necessary and at least once every year, assess whether any 
substantial changes to the grounds for issuing the blocking orders have occurred and-4# 
particular, whether the conditions of paragraph 4 continue to be met. 


en nats Tee re C nm mercR Ee Bh ee 
revocation of such _order, wWhere necessary in the light of the outcome of that assessment 
or te—take—account—of justified +equests—or other relevant information, including 


information obtained through the reports referred to in Article +8 17(5a) and—(6), 
respectively an order shall be modified or repealed reversed by the issuing authority, 
where relevant at the request of the Coordinating Authority. Fhe-provisions-efthis 
Section shall apphte-such requests, mutatis mutandis. 


Article 17 


Additional rules regarding blocking orders 


1. Fhe-Coordinatine Authority of establishment shall issuethe A blocking orders-+referred+te 
in- Article shall be issued using the template set out in Annex VII. Blocking orders shall 


include: 


(a) where applicable, the isa. to the ae ue Mein resource wae Doves by 
the EU Centre,—andth 2 e ners: 
cafesuseds cocci Rade Mat > Astle 16(5) and, Wied scene 
Frequirements-set-pursuantte Article 1 8(6); 


> 


(b) identification details of the eempetent—udicial_autherity—or—the—independent 
administrative authority issuing the blocking order and authentication of the blocking 


order by that authority; 
(c) the name of the provider and, where applicable, its legal representative; 


(d) clear information enabling the provider to identify and locate the child sexual 
abuse material and the specific service in respect of which the detection order is 
issued; 


(e) the start date and the end date of the blocking order; 
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4a. 


33 


(ea) the limits referred to in Article 16(5); 


(f) a sufficiently detailed statement of reasons explaining why the blocking order is 
issued; 


(fa) reporting requirements pursuant to paragraph 5a; 


(g) areference to this Regulation as the legal basis for the blocking order; 


(h) the date, time stamp and electronic signature of the judicial autherity—or—the 
independent administrative-authority issuing the blocking order; 


(i) easily understandable information about the redress available to the addressee of the 
blocking order, including information about redress to a court and about the time 
periods applicable to such redress. 


The competent judicial authority _er_independent_administrative authority issuing the 
blocking order shall address it to the main establishment of the provider or, where 
applicable, to its legal representative designated in accordance with Article 24. 


The blocking order shall be transmitted to the provider’s point of contact referred to in 
Article 23(1) by electronic means capable of producing a written record under 
conditions that allow to establish the authentication of the sender, including the 
accuracy of the date and the time of sending and receipt of the order, to the 
Coordinating Authority in the Member State in which the order was issued of 
establishment and to the EU Centre, through the system established in accordance with 
Article 39(2). 


The blocking order shall be drafted-transmitted in any of the official languages declared 
by the provider pursuant to Article 23(3). 


Sic? Gane tie et as oe eo et 
oefficiaHanguages-declared_by_the provider_in-accordance_with-article 23). 


If the provider cannot execute the blocking order on grounds of force majeure or de 
facto impossibility not attributable to it, including for objectively justifiable technical 
or operational reasons, it shall, without undue delay, inform the authority issuing the 
order of those grounds, using the template set out in Annex yy. 


PCY comment: not necessary considering wording of Article 23(3). 
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5a. 


If the provider cannot execute the blocking order because it contains manifest errors or 
does not contain sufficient information for its execution, the provider shall, without undue 
delay, request the necessary clarification te from the authority issuing the order 


Coordinatine Authority_of establishment using the template set out in Annex VIII. 


The provider shall, without undue delay and using the template set out in Annex xx, 
inform the issuing authority of the measures taken to execute the blocking order, 
indicating, in particular, whether the provider has prevented access to child sexual 
abuse material. 


The authority issuing the order may shall require the provider to report to it at 
regular intervals on the measures taken and their functioning to execute a blocking 
order, including the effective and proportionate limitations and safeguards provided 
for. 


Upon request of the issuing authority, the provider shall also provide, without undue 
delay, such reports or any other information relating to the execution of the blocking 
order needed for the purpose of the assessment referred to in Article 16(7). 


The Commission shall be empowered to adopt delegated acts in accordance with Article 86 
in order to amend Annexes VII, yy, aad-VUI and xx where necessary to improve the 
templates in view of relevant technological developments or practical experiences gained. 


Article 18 


Redress and provision of information +xfermation-and-repertine_of blecking_erders 


la. 


34 


Providers of internet access services that have received a blocking order—as-wel-as and 
users who provided erwere-prevented from accessing a-specific item of blocked material 

; shall have a right to 
effective redress. That right shall include the right to challenge the blocking order before 
the courts of the Member State of the competent judicial autherity—orindependent 
administrative authority that issued the blocking order.*4 


If the order is repealed reversed as a result of a redress procedure, the provider shall 
without undue delay reinstate access to the material, without prejudice to the 
possibility to enforce its terms and conditions in accordance with Union and national 
law. 


PCY comment: the PCY notes that while there are legal reasons for an extensive right to 


judicial redress (standing), they are also important to bear in mind the potential effects of such 


an. 


extensive right. 
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2: When the blocking order becomes final, the ecempetentjudicial-autherityor independent 
administrative authority that issued the blocking order shall, without undue delay, transmit 
a copy thereof and copies of information it has received pursuant to Article 17 (4a) to 
(5a) the Coordinating Authority ef—establishment. The Coordinating Authority of 
establishment shall then, without undue delay, transmit a-cepy copies thereof to all other 
Coordinating Authorities and the EU Centre through the system established in 
accordance with Article 39(2). 


For the purpose of the first subparagraph, a blocking order shall become final upon the 
expiry of the time period for appeal where no appeal has been lodged in accordance with 
national law or upon confirmation of the removal order following an appeal. 


3. The provider shall establish and operate an accessible, age-appropriate and user-friendly 
mechanism that allows users to submit to itwitht1-a+easonabletimeframe, complaints 
about alleged infringements of its obligations under this Section. It shall process such 
complaints in an objective, effective and timely manner. 


4. Where a provider prevents users from accessing the content chiid-sexual-abuse-material 
the—-aniferm—+resourcetocaters pursuant to a blocking order issued—+n—accordance—with 
Article 7, it shall take reasonable measures to inform-the those users of the following: 


(a) the fact that it does so pursuant to a blocking order and the reasons for doing so; 


(c) the users? right of users who provided the blocked material to judicial redress 
referred to in paragraph 1, their rights of users to submit complaints to the provider 
through the mechanism oe to in paragraph 3 and to the Coordinating Authority 
in accordance with Article 34,-as-+wel-asthe#+ichtte-submit the requests referred to 
in-paragraphs. 


5. oe a Me 
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Section 5a 
Delisting obligations 


Article 18a 
Delisting orders 


The competent authority ef-establishment shall have the power to issue an order, in 
accordance with relevant national requirements, requiring a provider of an online 
search engine under the jurisdiction of that Member State to take reasonable 
measures to delist an online location where child sexual abuse material can be found 
from appearing in search results in all Member States. The competent authorities 
may make use of the list of uniform resource locators included in the database of 
indicators, in accordance with Article 44(2), point (b) and provided by the EU Centre. 


By deviation from the first subparagraph, and without causing undue delays in the 
process of issuance of those orders, Member States may decide that such orders can 
only be issued by a judicial authority at the request of the competent authority. 
Where a Member State makes use of this possibility, it shall inform the Commission 
thereof and maintain this information updated. The Commission shall make the 
information received publicly available and maintain this information updated. 


The provider shall execute the delisting order without undue delay and in any event 
within a reasonable time period set by the issuing authority-ene-weel_of receipt-ofthe 
order. The provider shall take the necessary measures to ensure that it is capable of 
reinstating the delisted online location to appear in search results in accordance with 
Article 18¢(2). 


A delisting order shall be issued where the following conditions are met: 


(a) the delisting is necessary to prevent the dissemination of the child sexual abuse 
material in the Union, having regard in particular to the need to protect the 
rights of the victims; 


(b) URLs specified in the delisting order search-results correspond, in a sufficiently 
reliable manner, to online locations where child sexual abuse material can be 
found. 
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4. The issuing authority shall specify in the delisting order the period during which it 
applies, indicating the start date and the end date. 


The period of application of delisting orders shall not exceed five years. 


5. The Coordinating Authority or the issuing authority shall, where necessary and at 
least once every year, assess whether any substantial changes to the grounds for 
issuing the delisting orders have occurred and whether the conditions of paragraph 4 
continue to be met. 


Where necessary in the light of the outcome of that assessment or information of the 
reports referred to in Article 18b(6) an order may be modified or repeated reversed 
by the issuing authority, where relevant at the request of the Coordinating Authority. 


Article 18aa* 
Procedure for cross-border delisting orders*® 


1. Subject to Article 18a, where the provider of an online search engine does not have its 
main establishment or legal representative in the Member State of the authority that 
issued the delisting order, that authority shall, simultaneously to issuing the order to 
the provider of the online search engine, transmit a copy of the delisting order to the 
Coordinating Authority of the Member State where the online search engine provider 
has its main establishment or where its legal representative resides or is established. 
If the receiving Coordinating Authority is not the competent authority, it shall 
transmit the order to the competent authority for the purpose of the procedure of this 
Article. 


The delisting order shall be transmitted in any of the official languages declared by 
the provider pursuant to Article 23(3). 


2. Where an online search engine provider receives a delisting order as referred to in 
this Article, it shall take the measures provided for in Article 18a and take the 
necessary measures to ensure that it is capable of reinstating the delisted online 
location to appear in search results in accordance with Article 18c(2). 


3. The competent authority of the Member State where the online search engine 
provider has its main establishment or where its legal representative resides or is 
established may, on its own initiative, within 72 hours of receiving the copy of the 
delisting order in accordance with paragraph 1, scrutinise the delisting order to 
determine whether it seriously or manifestly infringes this Regulation or the 
fundamental rights and freedoms guaranteed by the Charter and whether it complies 
with its national constitutional law. 


35. PCY comment: this article may need to be reviewed pending the outcome of the discussion on 


Art. 14a (cross-border removal orders). 


36 ~~ PCY comment: see footnote under Article 14a. 
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Where it finds an infringement or a constitutional incompatibility, it shall, within the 
same period, adopt a reasoned decision to that effect. 


4. The competent authority shall, before adopting a decision pursuant to the second 
subparagraph of paragraph 3, inform the competent authority that issued the 
delisting order of its intention to adopt the decision and of its reasons for doing so. 


3. Where the competent authority adopts a reasoned decision in accordance with 
paragraph 3 of this Article, it shall, without delay, transmit that decision, if necessary 
through the Coordinating Authority, to the authority that issued the delisting order, 
the online search engine provider and the EU Centre. 


Where the decision finds an infringement or a constitutional incompatibility pursuant 
to paragraph 3 of this Article, the delisting order shall cease to have legal effects. 


6. Upon receiving a decision finding an infringement or a constitutional incompatibility 
communicated in accordance with paragraph 5, the online search engine provider 
concerned shall without undue delay reinstate the delisted online location to appear in 
search results, without prejudice to the possibility to enforce its terms and conditions 
in accordance with Union and national law. 


Article 18b 
Additional rules regarding delisting orders 


iF A delisting order shall be issued using the template set out in annex zz. Delisting 
orders shall include: 


(a) identification details of the authority issuing the delisting order and 
authentication of the order by that authority; 


(b) the name of the provider and, where applicable, its legal representative; 


(c) clear information enabling the provider to identify and locate the child sexual 
abuse material; 


(d) the start and end date of the delisting; 


(e) a sufficiently detailed statement of reasons explaining why the delisting order is 
issued; 
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(f) reporting requirements pursuant to point 6; 
(g) areference to this Regulation as the legal basis for delisting; 


(h) the date, time stamp and electronic signature of the authority issuing the 
delisting order; 


(i) easily understandable information about the redress available, including 
information about redress to a court and about the time periods applicable to 
such redress. 


The authority issuing the delisting order shall address it to the main establishment of 
the provider or, where applicable, to its legal representative designated in accordance 
with Article 24. 


The delisting order shall be transmitted to the provider’s point of contact referred to 
in Article 23(1) by electronic means capable of producing a written record under 
conditions that allow to establish the authentication of the sender, including the 
accuracy of the date and the time of sending and receipt of the order to the 
Coordinating Authority in the Member State in which the order was issued ef 
establishment and to the EU Centre, through the system established in accordance 
with Article 39(2). 


The delisting order shall be transmitted in any of the offical languages declared by 
the provider pursuant to Article 23(3). 


WAR Ee. Seno aaron ea aaninn 


most uperiant clement: adie The the execution of the-order- ito any of she 
officaHanguages-declared-by_the provider_in-accordance-with Article 233). *7 


If the provider cannot execute the delisting order on grounds of force majeure or de 
facto impossibility not attributable to it, including for objectively justifiable technical 
or operational reasons, it shall, without undue delay, inform the authority issuing the 
order of those grounds, using the template set out in Annex qq. 


If the provider cannot execute the delisting order because it contains manifest errors 
or does not contain sufficient information for its execution, the provider shall, without 
undue delay, request the necessary clarification from the authority issuing the order, 
using the template set out in Annex pp. 


PCY comment: not necessary considering wording of Article 23(3). 
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The provider shall, without undue delay and using the template set out in Annex ww, 
inform the issuing authority of the measures taken to execute the delisting order, 
indicating, in particular, whether the provider has prevented search results for the 
online location with child sexual abuse material to appear. 


The authority issuing the order may require the provider to report to it regularly on 
the measures taken to execute a delisting order. 


The Commission shall be empowered to adopt delegated acts in accordance with 
Article 86 in order to amend Annexes zz, qq and pp where necessary to improve the 
templates in view of relevant technological developments or practical experiences 
gained. 


Article 18c 
Redress and provision of information 


Providers of online search engines that have received a delisting order and users that 
provided the material to a delisted online location shall have a right to effective 
redress. That right shall include the right to challenge the delisting order before the 
courts of the Member State of the authority that issued the delisting order. 


If the order is repealed reversed as a result of a redress procedure, the provider shall 
without undue delay reinstate the delisted online location to appear in search results, 
without prejudice to the possibility to enforce its terms and conditions in accordance 
with Union and national law. 


When the delisting order becomes final, the issuing authority shall, without undue 
delay, transmit a copy thereof and information it has received pursuant to Article 18b 
(4) to (6) to the Coordinating Authority efestablishment. The Coordinating Authority 
ofestablishment shall then, without undue delay, transmit a copies thereof to all other 
Coordinating Authorities and the EU Centre through the system established in 
accordance with Article 39(2). 


For the purpose of the first subparagraph, a delisting order shall become final upon 
the expiry of the time period for appeal where no appeal has been lodged in 
accordance with national law or upon confirmation of the delisting order following an 
appeal. 


The provider shall establish and operate an accessible, age-appropriate and user- 
friendly mechanism that allows users to submit to it complaints about alleged 
infringements of its obligations under this Section. It shall process such complaints in 
an objective, effective and timely manner. 
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Where a provider prevents users from obtaining search results for child sexual abuse 
material corresponding to an online location pursuant to a delisting order, it shall 
take reasonable measures to inform users that provided the material to a delisted 
online location and those users of the following: 


(a) the fact that it does so pursuant to a delisting order; 
(b) the right of users that provided the material to a delisted online location to 


judicial redress referred to in paragraph 1 and users’ right to submit 
complaints to the Coordinating Authority in accordance with Article 34. 


Section 6 
Additional provisions 


Article 19 


Liability of providers 


Providers of relevant information society services shall not be liable for child sexual abuse offences 


if and insofar as selebbecause they carry out, in good faith, the- necessary activities to comply 
with the requirements-ofthis Regulation, in particular activities aimed at assessing and mitigating 
risk, detecting, identifying, reporting, removing, disabling efaccess to, blocking or delisting from 


search results reperting online child sexual abuse #-accordance-with these requirements. 


Article 20 
Victims’ right to information 


Persons residing in the Union shall have the right to receive, upon their request, from the 
Coordinating Authority destenatedby in the Member State where they reside, information 
regarding any instances where the dissemination of known child sexual abuse material 
depicting them is reported to the EU Centre pursuant to Article 12. Persons with 
disabilities shall have the right to ask and receive such an information in a manner 
accessible to them. 


That Coordinating Authority shall transmit the request to the EU Centre through the 
system established in accordance with Article 39(2) and shall communicate the results 
received from the EU Centre to the person making the request. 
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De The request referred to in paragraph | shall indicate: 
(a) the relevant item or items of known child sexual abuse material; 


(b) where applicable, the individual or entity that is to receive the information on behalf 
of the person making the request; 


(c) sufficient elements to demonstrate the identity of the person making the request. 
3: The information referred to in paragraph 1 shall include: 

(a) the identification of the provider that submitted the report; 

(b) the date of the report; 


(c) whether the EU Centre forwarded the report in accordance with Article 48(3) and, if 
so, to which authorities; 


(d) whether the provider reported having removed or disabled access to the material, in 
accordance with Article 13(1), point (1). 


Article 21 
Victims’ right of assistance and support for removal 


1. Providers of hosting services shall provide reasenable—-assistance, on request, to persons 
residing in the Union that seek to have one or more specific items of known child sexual 
abuse material depicting them removed or to have access thereto disabled by the provider. 


2: Persons residing in the Union shall have the right to receive support from the EU Centre, 
upon their request, to and via frem the Coordinating Authority designated—by in the 
Member State where they—persen resides; te—-request_assistance,support_from the EU. 
Centre when they seek to have a provider of hosting services remove or disable access to 
one or more specific items of known child sexual abuse material depicting them. Persons 
with disabilities shall have the right to ask and receive any information relating to such 
support in a manner accessible to them. 


That Coordinating Authority shall transmit the request to the EU Centre through the 
system established in accordance with Article 39(2) and shall communicate the results 
received from the EU Centre to the person making the request. 
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a: The requests referred to in paragraphs | and 2 shall indicate the relevant item or items of 
child sexual abuse material. 


4. The EU Centre’s support referred to in paragraph 2 shall include, as applicable: 


(a)}—_suppertn-connection to-requestine the _providers_assistance teferred te in paragraph 
4: 


> 


(b) verifying whether the provider removed or disabled access to that item or those 
items, including by conducting the searches referred to in Article 49(1); 


(c) notifying the item or items of known child sexual abuse material depicting the person 
to the provider and requesting removal or disabling of access, in accordance with 
Article 49(2); 


(d) where necessary, informing the Coordinating Authority of establishment of the 
presence of that item or those items on the service, with a view to the issuance of a 
removal order pursuant to Article 14. 


10833/23 FL/ml 56 
ANNEX JAL1 LIMITE EN 


38 


39 


Article 2274 ? 
Preservation of information 


Providers of hosting services and providers of interpersonal communications services shall 
preserve the neeessary content data and other data processed that is necessary for taking 
is-connectionte the measures taken to comply with this Regulation and the personal data 
generated through such processing, when the following measures have been taken or for 


the purposes of complaints or redress procedures cemplaints-onbfer-one-or-meoreofthe 
folowing purposes, as applicable: 


(xa) insofar as strictly necessary for using the technologies referred to in Article 10, 
involving in particular the automatic, intermediate and temporary preservation 
of such data for the use of the indicators provided by the EU Centre, as well as 
for applying the safeguards referred to in Article 10, when executing a detection 
order issued pursuant to Article 7; 


PCY comment: recital 39 could be amended as follows: “(39) To avoid disproportionate 
interferences with users’ rights to private and family life and to protection of personal data, 
the data related to instances of potential online child sexual abuse should not be preserved by 
providers of relevant information society services, unless and for no longer than necessary for 
one or more of the purposes specified in this Regulation and subject to an appropriate 
maximum duration. In that regard, the requirements to preserve such data in connection to the 
execution of detection orders should not be understood as allowing or requiring the 
preservation of all users’ data processed for such detection purposes in general. They should 
rather be understood as requiring only the preservation of content data and other data 
processed insofar as this is strictly necessary to use the relevant technologies meeting the 
requirements of this Regulation, covering in particular caching-like activities involving the 
automatic and intermediate preservation for purely technical reasons and for very short 
periods of time needed to use the relevant indicators to detect possible child sexual abuse 
online, as well as to apply the safeguards required under this Regulation in connection to the 
use of those technologies, covering in particular the application of measures to prevent, 
detect and remedy misuse, to ensure regular human oversight and to carry out regular reviews. 
As those preservation requirements relate only to this Regulation, they should not be 
understood as affecting the possibility to store relevant content data and traffic data in 
accordance with Directive 2002/58/EC or the application of any legal obligation to preserve 
data that applies to providers under other acts of Union law or under national law that is in 
accordance with Union law.” 


PCY comment: once more clarity is achieved on the detection order, the PCY is of the view 
that this article must be discussed in terms of its scope in order to minimise legal risks, in 
particular in view of the fact that this article covers content data in interpersonal 
communications. 
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(a) executing a-detection-order issued _pursuanttoArticle-7,or a removal order issued 


pursuant to Article 14 [or a blocking order pursuant to Article 16 or a delisting 
order pursuant to Article 18a]*°; 


(b) reporting information that indicate potential online child sexual abuse to the EU 
Centre pursuant to Article 12; 


(c) blocking the account of, or suspending or terminating the provision of the service to, 
the user concerned; 


(d) handling users’ complaints to the provider or to the Coordinating Authority, or the 
exercise of users’ right to administrative or judicial redress, in respect of alleged 
infringements of this Regulation. 


(e}— 


Upon a request respending—to—requests issued by a competent law—enfercement 
authoritytes and jedicial-autherities_[in accordance with the applicable law], providers 
shall with-a-view-te provideing them requesting authority with the necessary information 
for the prevention, detection, investigation or prosecution of child sexual abuse offences; 
or the handling of complaints or admininstrative or judicial redress proceedings, 
insofar as the content data and other data have been preserved for one of the purposes in 
paragraphs 1(a) to (d). relate to-a report that the-provider has-_submitted tothe EU Centre 
pursuantte Article 42. 


As regards the first subparagraph, point (a), the provider may also preserve the information 
for the purpose of improving the effectiveness and accuracy of the technologies to detect 
online child sexual abuse for the execution of a detection order issued to it in accordance 
with Article 7. However, it shall not store any personal data for that purpose. 


Providers shall preserve the information referred to in paragraph 1 for no longer than 
necessary for the applicable purpose and, in any event, no longer than 12 months from the 
date of the measures taken that led to the obligation to preserve the information 
content datiinid ether dita precessed reper ote the tenia tat disabling of eceies 
whichevereceurs-first. They shall subsequently irrevocably delete the information. 


Providers Fhey—shall, upon request from the competent nattenalauthority —oer—court, 
preserve the information for a further specified period, set by thatthe requesting authority 
er-court-where and to the extent necessary for ongoing administrative or judicial redress 
proceedings, as referred to in paragraph 1, point (d). 


40 


PCY comment: the PCY would like to hear the views of delegations on the need for 


inclusion of the blocking and the delisting orders in this Article. 
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a Providers shall ensure that the information referred to in paragraph 1 is preserved in a 
secure manner and that the preservation is subject to appropriate technical and 
organisational safeguards. Those safeguards shall ensure, in particular, that the information 
can be accessed and processed only for the purpose for which it is preserved, that a high 
level of security is achieved and that the information is deleted upon the expiry of the 
applicable time periods for preservation. Providers shall regularly review those safeguards 
and adjust them where necessary. 


4. PS OEY WEP a NE SY RN 


pecirdine tn oparackanll le-diccontnued: 


Article 22a 


Keeping of logs*! 


1. Providers of hosting services and providers of interpersonal communications services shall 
record, in respect of any a-detailed_eventinfermation-on processing of content and other data 
in connection with the execution of detection order pursuant to Article 7, fand-ether-measures 


£ this Regulation! 


This-eventinformation-shali inchide-the time and duration of the processing and, where 
applicable, the person performing the processing. 


2. The logs shall only be used for the verification of the lawfulness of the processing, for self- 
monitoring, for ensuring data integrity and data security as well as for the purposes of 
criminal or disciplinary proceedings. 


3. Providers shall keep the information contained in the logs referred to in paragraph 1 for no 
longer than necessary for the applicable purpose and, in any event, no longer than five years 
from the date of the measures taken that led to the obligation to preserve the information 
recorded in those logs. They shall subsequently irrevocably delete the information. 


They shall, upon request from the competent national authority or court, keep the 
information for a further specified period, set by that the requesting authority or court, where 
and to the extent necessary for one of the purposes referred to in paragraph 2. 


41 PCY comment: it has been proposed to develop the data protection aspects of this Regulation 
in addition to the GDPR. The PCY wishes to hear the delegations’ views. 
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Article 23 
Points of contact 


i Providers of relevant information society services shall establish a single point of contact 
allowing for direct communication, by electronic means, with the Coordinating 
Authorities, other competent authorities of the Member States, the Commission and the EU 
Centre, for the application of this Regulation. 


2: The providers shall communicate to the EU Centre and make public the information 
necessary to easily identify and communicate with their single points of contact, including 
their names, addresses, the electronic mail addresses and telephone numbers. 


3. The providers shall specify in the information referred to in paragraph 2 the official 
language or languages of the Union, which can be used to communicate with their points 
of contact. 


The specified languages shall include at least one of the official languages of the Member 
State in which the provider has its main establishment or, where applicable, where its legal 
representative resides or is established. 


Article 24 
Legal representative 


1. Providers of relevant information society services which do not have their main 
establishment in the Union shall designate, in writing, a natural or legal person as its legal 
representative in the Union for the purposes of this Regulation. 


2 The legal representative shall reside or be established in one of the Member States where 
the provider offers its services. 


3: The provider shall mandate its legal representatives to be addressed in addition to or 
instead of the provider by the Coordinating Authorities, other competent authorities of the 
Member States and the Commission on all issues necessary for the receipt of, compliance 
with and enforcement of orders and decisions issued in relation to this Regulation, 
including detection orders, removal orders and, blocking orders and delisting orders. 


4. The provider shall provide its legal representative with the necessary powers and resources 
to cooperate with the Coordinating Authorities, other competent authorities of the Member 
States and the Commission and to comply with the orders and decisions referred to in 
paragraph 3. 


a The designated-legal representative may be held liable for non-compliance with obligations 
of the provider under this Regulation, without prejudice to the liability and legal actions 
that could be initiated against the provider. 
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6. The provider shall notify the name, address, the electronic mail address and telephone 
number of its legal representative designated pursuant to paragraph | to the Coordinating 
Authority in the Member State where that legal representative resides or is established, and 
to the EU Centre. The provider or the legal representative Fhey-shall ensure that that 
information is up to date and publicly available. 


Ve The designation of a legal representative within the Union pursuant to paragraph | shall 
not amount to an establishment in the Union. 
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CHAPTER III 


SUPERVISION, ENFORCEMENT AND COOPERATION 


Section 1 
Coordinating Authorities of the Member States-forchild-sexual- abuse issues” 


Article 25% 


Coordinating Authorities forehild-sexuaLlabuseissues and other competent authorities 


1. Member States shall, by {Pate— #re-eighteen months from the date of entry into force of 
this Regulation}, designate one or more competent authorities as responsible for the 


application, and supervision and enforcement of this Regulation Geempetentautherties-}. 


la. Where a Member State designates more than one competent authority, it shall 
appoint one of those competent authorities as Coordinating Authority. Where it 
designates only one competent authority, that competent authority shall be the 
Coordinating Authority. 


2. Member States shall, by the date referred to in paragraph 1, designate one of the competent 
authorities as their Coordinating Authority for child sexual abuse issues (‘Coordinating 
Authority’). 


The Coordinating Authority shall be responsible for all matters related to the application 
and enforcement of this Regulation in the Member State concerned, unless that Member 
State has assigned certain specific tasks or sectors to other competent authorities. 


42 PCY comment: see in annex a list of the tasks of the Coordinated Authorities. 


43 PCY comment: the new logic could be explained in a recital, as follows: 


“With a view to leaving Member States a degree of flexibility so as to implement solutions 
best adapted to their particular circumstances, whilst also ensuring the coordination at 
domestic level and cooperation at EU level needed to ensure the consistent, efficient and 
effective application of this Regulation, Member States should be able to designate several 
competent authorities yet be required in that case to appoint one of them as the Coordinating 
for which certain tasks are exclusively reserved under this Regulation. Therefore, each 
mention of competent authorities in this Regulation should be interpreted as referring to the 
relevant competent authorities designated by the Member States, including where relevant 
Coordinating Authorities, while each mention of Coordinating Authorities should be 
interpreted as referring to Coordinating Authorities only, to the exclusion of any other 
competent authorities that the Member States may have designated. Member States should 
also be able to provide for the ex post administrative or judicial review of the orders issued by 
competent authorities, in accordance with national law, including when such review is not 
specifically provided for in this Regulation.” 
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The Coordinating Authority shall in any event be responsible for ensuring coordination at 
national level in respect of these all matters relating to the application, supervision and 


enforcement of this Regulation and—fer—contributine to—the—effective_efficient_and 
consistent applheation, and enforcement ofthis Resulation throuchout the Union. 


3: Where a Member State designates more than one competent authority #1-additientethe 
Coordinating Authority, it shall ensure that the respective tasks of those authorities and-ef 


the-Coordinatine Authority including those of the Coordinating Authority, are clearly 
defined and that they or iae ese y and eliecuvely when peor ie their tasks. The 


tell Me so eS ee Cen etd ee an ee 


4. Within one week after the designation of the competent authorities, including the 
Coordinating Authorities and-other-competent authorities pursuantte-paracrapht, Member 
States shall make publicly available, and communicate to the Commission and the EU 
Centre, the names of the#—CeordinatingAuthority—and—other—compentent those 
authorities as well as their respective tasks or sectors. They shall keep that information 
updated. 


3 Each-Member States shall easurethat-acentact peimtis-desienated or establish a contact 


point within its the-Coordinating Authority’s office to handle requests for clarification, 
feedback and other communications in relation to all matters related to the application and 
enforcement of this Regulation+n—that_ Member—State. Member States shall make the 
information on the contact point publicly available and communicate it to the EU Centre. 
They shall keep that information updated. 


6. Within two weeks after the designation of the Coordinating Authorities pursuant to 
paragraph 2, the EU Centre shall set up an online register listing the Coordinating 
Authorities and their contact points. The EU Centre shall regularly publish any 
modification thereto. 


ts Competent authorities Coordinating—AuthorHies may, where necessary for the 
performance of their tasks under this Regulation, request through the Coordinating 


Authority, the assistance of the EU Centre in carrying out those tasks, in particular, by 
requesting the EU Centre to: 


(a) provide certain information or technical expertise on matters covered by this 
Regulation; 


(b) assist in assessing, in accordance with Article 5(2), the risk assessment conducted or 
updated or the mitigation measures taken by a provider of hosting or interpersonal 
communications services under the jurisdiction of the Member State that designated 


the requesting competent authority Coordinating Authority; 
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(c) provide an opinion on verify the possible need fer—-a-eempetent—autherity to 
request competent national authorities tessue the issuance of a detection order,-a 
in respect of a service under the jurisdiction of the 


removalorder, ora blocking orderi 
Member State that designated that Coordinatine Authority; 


[(d) provide an opinion on vert the effectiveness of a detection order oo cmeya 
order issued upenthe request of the requesting Coordinating Authoritys. ]4 


pea alls el aes ee el eee oe 


popstante pap hE 
Article 26 


Requirements for Ceoerdinating competent Authorities 


i Member States shall ensure that the competent authorities Coordinating Authorities that 
they have designated carry out perferm their tasks under this Regulation in an objective; 
impartial transparent andtimely and non-discriminatory manner, while fully respecting 
the fundamental rights ef all -parties_affected47. Member States shall ensure that their 
Coordinating Authorities those authorities have adequate technical, financial and human 
resources to carry out their tasks. 


44 PCY comment: to be revised pending further discussions on detection orders. 

45 PCY comment: moved to Art 43(5)(b) on the EU Centre. 

46 PCY comment: this recital (copied from recital 35 TCO) could be included: “For the purposes 
of this Regulation, Member States should designate competent authorities. This should not 
necessarily imply the establishment of a new authority and it should be possible to entrust an 
existing body with the functions provided for in this Regulation. This Regulation should 
require the designation of authorities competent for issuing removal orders, scrutinising 
removal orders, overseeing specific measures and imposing penalties, while it should be 
possible for each Member State to decide in accordance with the relevant requirements of this 
Regulation and the Charter, on the number of competent authorities to be designated and 
whether they are administrative or law enforcement or judicial. Member States should ensure 
that the competent authorities fulfil their tasks in an objective and non-discriminatory manner 
and do not seek or take instructions from any other body in relation to the exercise of the tasks 
under this Regulation. This should not prevent supervision in accordance with national 
constitutional law. Member States should communicate the competent authorities designated 
under this Regulation to the Commission, which should publish online a register listing the 
competent authorities. That online register should be easily accessible to facilitate the swift 
verification of the authenticity of removal orders by the hosting service providers.” 

47 PCY comment: wording copied from Art. 13(2) of the TCO Regulation. 
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Those authorities Fhe-Coordinating Authorities shall not seek or take instructions 


from any other body in relation to carrying out their tasks under this Regulation*®. 


Regulation, the Coordinating Authorities aa aet wat i comple a Fe one 


> > > 


(a) — are legally and functionally independent from any other public authority: 


(d) neither seek nor take instructions from any other public authority or any private 


partys 


(e}—are-net-chareed-withtasks +elatine tethe_prevention_or-combatine of chid sexual 
keve-ofherthantuet tas ere 


23. Paragraph 2-1 shall not prevent supervision of the Coerdimating competent aAuthorities in 


accordance with national eenstitetienal law—tethe-extent that such-supervision_dees-not 
affect thei-independence-as-required under this Reeulation. 


3 4. The Coordinating Authorties_and-ether competent authorities shall ensure that their 
relevant members—of staff have the required qualifications, experience, integrity and 
technical skills to perferm carry out the application, supervision and enforcement 
under this Regulation duties. 


48 PCY comment: 1) This text could be included as a recital: “Member States should be free to 


designate any suitable national authority as competent authority for the purpose of this 
Regulation, provided that all requirements of this Regulation relating to them are fully 
respected, including as regards the competent authorities’ status and the manner in which 
they perform their tasks, their investigatory and enforcement powers, complaint-handling, 
cooperation at EU level and the involvement of a judicial authority erindependent 
administrative authority for the issuance of certain orders in accordance with this Regulation, 
as well as the requirements resulting from the Charter, in particular as regards effective 
judicial redress against the competent authorities’ decisions-arefally respected.” 


2) To address some delegations’ concerns that competent authorities would be getting 
“instructions” from judicial authorities, a recital could be added, as follows: “In order to 
ensure that the competent authorities designated under this Regulation carry out their tasks 
under this Regulation in an objective, adequate and responsible manner, in compliance with 
the fundamental rights guaranteed under the Charter and without any undue interference, 
certain requirements in this respect should be provided for. Those requirements should not be 
interpreted as precluding judicial review of the activities of competent authorities in 
accordance with EU law or with national law.” 
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49 
dis 


The management and other staff of the Coordinating Authorities shall, in accordance with 
Union or national law, be subject to a duty of professional secrecy both during and after 
their term of office, with regard to any confidential information which has come to their 
knowledge in the course of the performance of their tasks. Member States shall ensure that 
the management and other staff are subject to rules guaranteeing that they can carry out 
their tasks in an objective, impartial and independent manner, in particular as regards their 
appointment, dismissal, remuneration and career prospects. 


Section 2 
Powers of competent authorities the Coordinating Authorities of Member States 


Article 274” 
Investigatory and enforcement powers 


Where needed in order to fer-carrying out their tasks under this Regulation, competent 


authorities Coordinating Authorities er—other—competent—autherities shall have the 


following powers of investigation, in respect of conduct by providers of relevant 


information society services faHing—-within the-competenee under the jurisdiction of the 
their Member State that designated them: 


(a) the power to require those providers, as well as any other persons acting for purposes 
related to their trade, business, craft or profession that may reasonably be aware of 
information relating to a suspected infringement of this Regulation, to provide such 


information without undue delay-wi#hin-a+reasonable time period; 


(b) the power to carry out, or to request a judicial authority to order, on-site 
inspections of any premises that those providers or the-other-those persons referred 
te-4n-peintta} use for purposes related to their trade, business, craft or profession, or 
to request other public authorities to do so, in order to examine, seize, take or obtain 
copies of information relating to a suspected infringement ef this Regulation in any 
form, irrespective of the storage medium; 


(c) the power to ask any member of staff or representative of those providers or the other 
those persons to give explanations in respect of any information relating to a 


suspected infringement ef this-Regulatien—and to record the answers by any 
technical means; 


PCY comment: copied word for word from Art. 51 of the DSA as a baseline for further 


cussions. Differences include that (1) both the Coordinating and competent authorities are 


included; (ii) this text speaks about “user”, not “the recipient of a service’; (iii) in point 3b 
below the wording “or the infringement results in the regular and structural facilitation of 


child sexual abuse offences” has been maintained; and (iv) keeping the reference to 


“Susridiction” in the proposal rather than “competence” as in the DSA, given the extensive 


references to jurisdiction in the proposal. The restruturing of Articles 27 to 30 to ensure 
alignement with DSA has lead to the fact that some cross-references need to be corrected. 
This will be done once the text is stable. For the delegations’ ease, a clean version of Articles 


Zh 


-30 is in annex. The PCY is of the view that this section must be explained by recitals such 


as the ones in the DSA Regulation (114-116). 
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(d) the power to request information, including to assess whether the measures taken to 
execute a detection order, removal order,—er blocking order or delisting order 
comply with the requirements of this Regulation. 


2 Aieber States tase detonate estate posers tote Corti A ae iiies 
Article 2$ 
Enforcement powers 


2.4— Where needed for carrying out their tasks under this Regulation, competent authorities 


Coordinating Authorities shall have the following enforcement powers, in respect of 


providers of relevant information society services falling-within-the-competence under 
the jurisdiction of the their Member State that designated them: 


(a) the power to accept the commitments offered by those providers in relation to their 
compliance with this Regulation and to make those commitments binding; 


(b) the power to order the cessation of infringements ef this-Regulation and, where 
appropriate, to impose remedies proportionate to the infringement and necessary to 
bring the infringement effectively to an end or to request a judicial authority in 
their Member States to do so; 


(c) the power to impose fines, or request a judicial authority in their Member State to do 
so, in accordance with Article 35 for failure to comply with infringements—of this 


Regulation, including nes-ceomphanceavith any of the investigative orders issued 
pursuant to paragraph 1 of this Article 27 and+e-peint(b) ofthis paragraph; 


(d) the power to impose a periodic penalty payment, or to request a judicial authority 
to do so, in accordance with Article 35 to ensure that an infringement ofthis 
Resulatien is terminated in compliance with an order issued pursuant to point (b) of 
this subparagraph or for failure to comply with any of the orders issued pursuant to 


paragraph 1 of this Article. 2+and+te-peint(b)-ofthis-paracraph; 


(e) the power to adopt interim measures or to request the competent national judicial 
authority to do so, to avoid the risk of serious harm. 


3. As regards the first subparagraph +, points (c) and (d), competent authorities 
Coordinating Authorities shall also have the enforcement powers set out in those points 
alse-in respect of the other persons referred to in paragraph 1-Article27, for failure to 
comply with any of the orders issued to them pursuant to that paragraph Article. 4. They 
shall only exercise those enforcement powers after having provided those other persons in 
good time with all relevant information relating to such orders, including the applicable 
time-period, the fines or periodic payments that may be imposed for failure to comply and 
redress-the possibilities for redress. 
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Artiele29 
\dditional_ enki 


3.4— Where needed for carrying out their tasks under this Regulation, competent authorities 


Coordinating Authorities shall have—the—additional enforcement _powers_teferred_to—in 


paragraph, in respect of providers of relevant information society services faHing-within 
the-competence under the jurisdiction of their Member State, where that designated them, 


(a}—all other powers pursuant to this Articles27and28-to bring about the cessation of an 
infringement efthis-Regulatien have been exhausteds 


(b)—and the infringement has not been remedied or is continuing and is -persists; 


eauses-causing serious harm which cannot be avoided through the 
exercise of other powers available under Union or national law, also have the power 
to take the following measures: 


2#§! CooretisatineAthe tte hel Hip the ad Hea entoreeent posers to take the 


(a) to require the management body of the providers, without undue delay, to examine 


the situation, within-a+reasenable time-period andte- 


4}— adopt and submit an action plan setting out the necessary measures to terminate 
the infringement; 


44)— ensure that the provider takes those measures; and 
44#4)—report on the measures taken; 


(b) where the competent authorities consider that a provider of relevant 
information society services has not sufficiently complied with the requirements 
of point (a), that the infringement has not been remedied or is continuing and is 
causing serious harm, and that that infringement entails a criminal offence 
involving a threat to the life or safety of persons or the infringement results in 
the regular and structural facilitation of child sexual abuse offences, to request 


that the competent judicial authority erether independent administrative-authority 
of its the Member State that-designated the-Coordinatine Autherityte order the 


temporary restriction of access of users of the service concerned by the infringement 
or, only where that is not technically feasible, to the online interface of the provider 


on wich the infringement takes place. —herethe-Coordinatine Authority considers 


44 —_ he eee peste ict eatses seriotis Hata 


abuse-offences- 
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3.——The Coordinating Authority competent authorities shall, prior to submitting the request 
referred to in this paragraph 2, point (b), invite interested parties to submit written 
observations within a period that shall not be less than two weeks, describing the 
measures that it intends to request and identifying the intended addressee or 
addressees thereof. The provider, the intended addressee or addressees and any other 
third party demonstrating a legitimate interest shall be entitled to participate in the 


proceedings before the competent judicial authority or—ether—independent 


Cisse ee FTE ePIC rE ng CL 


The dnssiats panes EI 


(a})—deseribe the measures that it intends te-request:; 
denen hes led-add 1d C 
eens Lae RRR EE en ee Rigen "iia. dabei eaeaaeg 


4.———_Any measure ordered upon—the-request referred toin—paragraph2,_peint{b}, shall be 
proportionate to the nature, gravity, recurrence and duration of the infringement, without 
unduly restricting access to lawful information by users of the service concerned. 


The temperary-restriction of access shall be appb-for a period of four weeks, subject to the 


possibility for the competent judicial authority er—ether_independent—administrative 
authority of the Member State, in its order, to allow the Coordinating Autherty or other 
competent authoritiesinchidine the-Coordinatinge Authorities, to extend that period 


for further periods of the same lengths, subject to a maximum number of extensions set by 


a that judicial authority erether independent administrative authority. 


The Coordinatine—Authority competent authorities, imehding—the—Coordinating 
Authorities, referred to in the previeus second subparagraph shall only extend the 


period where-t-eensiders, having regard to the rights and tegit#mate-interests of all parties 
affected by the that restriction and all relevant faets—and circumstances, including any 
information that the provider, the addressee or addressees and any other third party that 
demonstrated a legitimate interest may provide to it, it considers that both of the following 
conditions have been met: 


(a) the provider has failed to take the necessary measures to terminate the infringement; 


(b) the temporary restriction does not unduly restrict access to lawful information by 
users of the service, having regard to the number of users affected and whether any 
adequate and readily accessible alternatives exist. 
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Where the Coordinating Authority competent authority—ineluding the—Ceordinating 
Authority, considers that the conditions set out in the fourth subparagraph, points (a) 


and (b) thesetwe—conditiens have been met but it cannot further extend the period 
pursuant to the fourth second subparagraph, it shall submit a new request to the competent 


judicial authority or-ether independent_administrative-autherity, as referred to in the 
first subparagraph, point (b). 


Article 30 
Common_previsiens_on_investigatery_and_enfercement powers 


4. +—The measures taken by the Coordinating Authorities competent authorities in the exercise 
of their investigatery_and-enforcement powers listed in paragraphs 1, 2 and 3 referredto 
in- Articles 27 28 and 29 shall be effective, dissuasive and proportionate, having regard, in 
particular, to the nature, gravity, recurrence and duration of the infringement ef this 
Resulatiern—or suspected infringement to which those measures relate, as well as the 
economic, technical and operational capacity of the provider of relevant information 
society services concerned; where relevant-appHeable. 


5.2.——Member States shall lay down specific rules and procedures for the exercise of the 
powers pursuant to paragraphs 1, 2 and 3 and shall ensure that any exercise of those 
the ivestigateryand- enforcement powers referred tein Articles 27, 28 and2%is subject to 
adequate safeguards laid down in the applicable national law in compliance with the 
Charter and with the general principles of Union law te-respectthe-fundamentalrights 
efal-parties-affected. In particular, those measures shall only be taken in accordance with 
the right to respect for private life and the rights of defence, including the rights to be heard 
and of access to the file, and subject to the right to an effective judicial remedy of all 
parties affected parties. 


Article 31 
Searches to verify compliance 


The competent authorities Coordinating Authorities shall have the power to carry out searches on 
publicly accessible material on hosting services to detect the dissemination of known or new child 
sexual abuse material, using the indicators contained in the databases referred to in Article 44(1), 
points (a) and (b), where necessary to verify whether the providers of hosting services under the 
jurisdiction of the Member State that designated the Coordinating Authorities comply with their 
obligations under this Regulation. 
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Article 32 
Netification-of nown-child sexuatabuse material 


as-the-reasons-for-the request a eeghe fall ales eles state a) ace Wc tae 


vohintary consideration” 


Section 3 
Other provisions on enforcement 
Article 33 
Jurisdiction*! 


1. The Member State in which the main establishment of the provider of relevant information 
society services is located shall have jurisdiction for the purposes of this Regulation. 


2 A provider of relevant information society services which does not have an establishment 
in the Union shall be deemed to be under the jurisdiction of the Member State where its 
legal representative resides or is established. 


Where a provider failed to appoint a legal representative in accordance with Article 24, all 
Member States shall have jurisdiction. Where a Member State decides to exercise 
jurisdiction under this subparagraph, it shall inform all other Member States and ensure 
that the principle of ne bis in idem is respected. 


50 PCY comment: It is the view of the PCY that this power can be explained and described in a 


recital that builds on recital 40 of the TCO Regulation and Article 16 DSA. The recital below 
clarifies that competent authorities can make use of notice and action mechanisms and be 
appointed as trusted flaggers: “Nothing in this Regulation precludes competent authorities 
designated therein to submit notices to providers of hosting services on the basis of notice and 
action mechanisms pursuant to Article 16 of Regulation (EU) 2022/2065 (Digital Services 
Act) to notify them of the presence of one or more specific items of known child sexual abuse 
material, nor to request the status of trusted flagger under the conditions established under 
Article 22 of that Regulation.” 

PCY comment: this Article will need to be adjusted to reflect the outcome of the discussions 
on cross-border removal orders and cross-border delisting orders. 


51 
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Article 34°? 


Right efusers-ef the-service to lodge a complaint 


Users and any body, organisation or association mandated to exercise the rights 
conferred by this Regulation on their behalf shall have the right to lodge a complaint 
against providers of relevant information society services alleging an infringement of 
this Regulation affectingthem against-providers—of relevant information society services 
with the Coordinating Authority designated-by in the Member State where the user is 
located resides-or is-established. 


Coordinating Authorities shall provide child-friendly mechanisms to submit a complaint 
under this Article and adopt a child-sensitive approach when handling complaints 
submitted by children, taking due account of the child's age, maturity, views, needs and 
concerns. 


The Coordinating Authority reeetinethe-complaint shall assess the complaint and, where 
appropriate, transmit it to the Coordinating Authority of establishment, accompanied, 
where appropriate, by its reasoning. 


Where the complaint falls under the responsibility of another competent authority in its 
Member State, that-designated the Coordinating Authority receiving the complaint,that 


Coordinating Authority shall transmit it to that ether-competent authority. 


During these proceedings, both parties shall have the right to be heard and receive 
appropriate information about the status of the complaint, in accordance with 
national law. 


Article 34b°3 
Representation 


Without prejudice to Directive (EU) 2020/1828 or to any other type of representation 
under national law, users of relevant information society services shall at least have 
the right to mandate a body, organisation or association to exercise the rights 
conferred by this Regulation on their behalf, provided the body, organisation or 
association meets all of the following conditions: 


(a) it operates on a non-profit basis; 
(b) it has been properly constituted in accordance with the law of a Member State; 


(c) its statutory objectives include a legitimate interest in ensuring that this 
Regulation is complied with. 


52 PCY comment: copied word for word from Art. 53 of the DSA. 


53 


PCY comment: copied word for word from Art. 86 of the DSA. To be discussed in relation to 


Articles 18(3) and 34. 


10833/23 FL/ml 72 


ANNEX 


JALI LIMITE EN 


34. 


45. 


Providers of relevant information society services shall take the necessary technical 
and organisational measures to ensure that complaints submitted by bodies, 
organisations or associations referred to in paragraph 1 of this Article on behalf of 
recipients of the service through the mechanisms referred to in Article xx are 
processed and decided upon with priority and without undue delay. 


Article 35%4 
Penalties** 


Member States shall lay down the rules on penalties applicable to infringements of the 
obligations pursuant to Chapters II and V of this Regulation by providers of relevant 
information society services within_theicompetence under their jurisdiction and shall 
take all the necessary measures to ensure that they are implemented in accordance with 
Article 27. 


Fhe-pPenalties shall be effective, proportionate and dissuasive. Member States shall, by 
[Date of application of this Regulation], notify the Commission of those rules and of those 
measures and shall notify it, without delay, of any subsequent amendments affecting them. 


Member States shall ensure that the maximum amount of fines that may be penalties 
imposed for an a failure to comply with an obligation laid down in Chapters Hand -V 
infrmeementof this Regulation shall be not exceed 6 % of the annual worldwide #wcome 
eretebal turnover of the providers concerned in the preceding financial business-year-of 
the-previder. 3-Member States shall ensure that the maximum amount of the fine that 
may be imposed Penalties for the supply of incorrect, incomplete or misleading 
information, failure to reply or rectify incorrect, incomplete or misleading information er 
and failure to submit to an en-s#e inspection shall be not exceed 1% of the annual income 
or worldwide glebalturnover of the precedingbusiness—year-ofthe provider or the-other 
person concerned in the preceeding financial year-referredteinArticle27. 


Member States shall ensure that the maximum amount of a periodic penalty payment shall 
be not exceed 5 % of the average daily worldwide glebal-turnover or income of the 


provider erthe-other-persen referred ton Article 27 in the preceding financial year per 
day, calculated from the date specified in the decision concerned. 

Member States shall ensure that the competent authorities, when deciding whether to 
impose a penalty and when determining the type and level of penalty, account is taken of 
all relevant circumstances, including: 


(a) the nature, gravity and duration of the infringement; 


(b) whether the infringement was intentional or negligent; 


54 PCY comment: copied word for word from Art. 52 of the DSA (except paragraph 4 that is 
taken from the TCO Regulation). 


55 


Le. 


PCY comment: this should be understood as administrative sanctions, not criminal sanctions, 


penalties (TCO and DSA use the wording “penalties” when these are in fact 


administrative sanctions). A recital should be included to clarify this issue. 
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(c) 
(d) 
(c) 


(f) 


(g) 


any-previous infringements by the provider or the other person; 
the financial strength of the provider or the other person; 


the level of cooperation of the provider or the other person with the competent 
authorities; 


the nature and size of the provider or the other person, in particular whether it is a 
micro, small or medium-sized enterprise; 


the degree of fault of the provider or other person, taking into account the technical 
and organisational measures taken by the provider it-to comply with this Regulation. 
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Section 4 
Cooperation 
Article 36 *° 
Identification and submission of online child sexual abuse 


Competent authorities shall submit to the EU Centre, without 
without undue delay and through the system established in accordance with Article 39(2): 


(a) specific items of material and transeripts extracts of written conversations that 

competent authorities Coordinating Authorities oF that the—competent judicial 

of a Member State have 

identified, after a diligent assessment, subject to adequate supervision oversight 

by judicial authorities*’, as constituting child sexual abuse material or the 

solicitation of children, as applicable, for the EU Centre to generate indicators in 
accordance with Article 44(3); 


(b) exact uniform resource locators indicating the electronic location of the 


information specifictems—of-material that competent authorities Coordinating 
Authorities or that competent judicial authorities_or other independent administrative 


autherties of a Member State have identified, after a diligent assessment, as 
consulGang oe sexu abuse material, i by las HOSES Spices net 


te remove oF disable access thereto and to-the lack: of cooperation by the competent 
for the EU Centre to compile the 
list of uniform resource locators in accordance with Article 44(3); 


56 


57 


PCY comment: the LEWP should continue working on this Article and return to it once more 
clarity is reached on the detection orders. 

PCY comment; the Commission has provided a text proposal to make clear that law 
enforcement can be involved in the process to determine the illegality of the content, under 
judicial supervision (recital xx “Member States should set up expedited procedures for the 
diligent assessment of suspected child sexual abuse, so as to allow for the swift submission to 
the EU Centre of the specific items of material, extracts of conversations and uniform 
resource locators concerned upon the reliable establishment of the illegality. With a view to 
facilitating and expediting such assessment, it should be possible for Member States to 
provide that competent authorities carry out the assessment of illegality of the content, under 


the oversight of the competent judicial authorities erindependentadministrative 
authorities.”’). 
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la. 


Member States shall take the necessary measures to ensure that the Coordinating 
Authorities that they designated receive, without undue delay, the material identified as 
child sexual abuse material, the transeripts extracts of written conversations identified as 
the solicitation of children, and the uniform resource locators, identified by a compen 
authority @ ada 
die Cosrigeie toa for sibiicion to ile EU Centre ar in aceordanoe Swill the first 
subparagraph. 


By deviation from paragraph 1, last subparagraph, Member States may decide that 
the submission to the EU Centre, in accordance with the requirements specified in 
points (a) and (b) of paragraph 1, can be carried out by the competent authorities 
without undue delay and through the system established in accordance with Article 
39(2). Where a Member State is making use of this possibility, the competent 
authority shall inform the Coordinating Authority of all the correspondence with the 
EU Centre. 


Upon the request of the EU Centre where necessary to ensure that the data contained in the 
databases referred to in Article 44(1) are complete, accurate and up-to-date, Coordinating 
AutherHies competent authorities shall verify or provide clarifications or additional 
information as to whether the conditions of paragraph 1, points (a) and (b) have been and, 
where relevant, continue to be met, in respect of a given submission to the EU Centre in 
accordance with that paragraph. 


Member States shall ensure that, where their law enforcement authorities receive a report 
of the dissemination of new child sexual abuse material or of the solicitation of children 
forwarded to them by the EU Centre in accordance with Article 48(3), a diligent 
assessment is conducted in accordance with paragraph 1 and, if the material or 
conversation is identified as constituting child sexual abuse material or as the solicitation 
of children, the Coordinating Autherity competent authority submits the material to the 
EU Centre, in accordance with that paragraph, within ene two months from the date of 
reception of the report or, where the assessment is particularly complex, #¥e six months 
from that date. 


They shall also ensure that, where the diligent assessment indicates that the material does 
not constitute child sexual abuse material or the solicitation of children, the Coordinating 
Authority is informed of that outcome and subsequently informs the EU Centre thereof, 
within the time periods specified in the first subparagraph*®. 


58 PCY comment: implications for law enforcement workload to be considered. 
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Article 37°? 
Cross-border cooperation among Coordinating Authorities 


i Where a Coordinating Authority that is not the Coordinating Authority of establishment 
has reasons to suspect that a provider of relevant information society services infringed this 
Regulation in a manner negatively affecting the users of the service in the Member 
State of that Coordinating Authority, it may shal-request the Coordinating Authority of 
establishment to assess the matter and to take the necessary investigatory and enforcement 
measures to ensure compliance with this Regulation. 


ration and ‘ake he necessary- see ecuecice: ae enforcerade measures a ensure 
estiphanee sch thpt Resto 


2 Fhe A request er-recommendation pursuant referred to in paragraph | shall be duly 
reasoned and at least indicate: 


(a) the point of contact of the provider as set out in Article 23; 


(b) a description of the relevant facts, the provisions of this Regulation concerned and 
the reasons why the Coordinating Authority that sent the request-erthe-Commission 
suspects, that the provider infringed this Regulation including the description of the 
negative effects of the alleged infringement; 


(c) any other information that the Coordinating Authority that sent the request—or+the 
Commission, considers relevant, including, where appropriate, information gathered 
on its own initiative and or suggestions for specific investigatory or enforcement 
measures to be taken, including interim measures. 


2: The Coordinating Authority of establishment shall take utmost account of the requests 


pursuant to paragraph 1 of this Article-assess_the-suspeeted infringement taking inte 
atmest_account the request_or_recommendation referred ton _paragraph_t. Where it 


considers that it has insufficient information to assesthe-suspected infringement-orte-act 
upon the request er-recemmendation and has reasons to consider that the Coordinating 
Authority that sent the request-erthe-Commissien, could provide additional information, it 
may request such information. The time period laid down in paragraph 4 shall be 
suspended until that additional information is provided. 


59 PCY comment: copied word for word from Art. 58 of the DSA. 
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60 


The Coordinating Authority of establishment shall, without undue delay and in any event 
not later than two months following receipt of the request er-recommendation pursuant 
referred—to in-paragraph 1, communicate to the Coordinating Authority that sent the 
request-oF-the- Commission, the outcome-ofits assessment of the Suspected bE eect 
vant, and; 
yere-eosicabla. an explanation: of the iavectigalony or Pipe measures taken or 
envisaged, if any, in relation thereto to ensure compliance with this Regulation. 


Article 38% 
Joint investigations 


Coordinating Authorities may participate in joint investigations, which may be coordinated 
with the support of the EU Centre, of matters covered by this Regulation, concerning 
providers of relevant information society services that offer their services in several 
Member States. 


Such joint investigations are without prejudice to the tasks and powers of the participating 
Coordinating Authorities and the requirements applicable to the performance of those tasks 
and exercise of those powers provided for in this Regulation. 


The participating Coordinating Authorities shall make the results of the joint investigations 
available to other Coordinating Authorities, the Commission and the EU Centre, through 
the system established in accordance with Article 39(2), for the fulfilment of their 
respective tasks under this Regulation. 


PCY comment: recital to be added, as follows: “Joint investigations” under Article 38 should 
be interpreted as formal inquiries by Coordinating Authorities concerning the compliance of 
the provider of relevant information society services with the obligations arising from this 
Regulation. Insofar as the penalties for infringements of those obligations provided for by the 
Member State concerned pursuant to this Regulation are not criminal in nature, “joint 
investigations” under Article 38 should not be interpreted as criminal investigations, which 
are usually conducted by law enforcement authorities under national law.” 
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Article 38a°! 
Mutual assistance 


The Coordinating Authorities and the other competent authorities of the Member States 
and the EU Centre Digital Services Coordinators and the Commission shall cooperate 
closely and provide each other with mutual assistance in order to apply this 
Regulation in a consistent and efficient manner. Mutual assistance shall include, in 
particular, exchange of information in accordance with this Article and the duty of 
the Digital_Services-Coordinator_of-establishment Coordinating Authority to inform all 


the other Coordinating Authorities Digital_Services—Coordinators—of—destination,_the 
Board-and-the-Commission about the opening of an investigation and the intention to 


take a final decision, including its assessment, in respect of a specific provider of a 


relevant information society tnternediary service. 


For the purpose of an investigation, a Coordinating Authority the DigitalServices 


Coordinator-of establishment may request a Coordinating Authority in another Member 
State other—Digital_Services—Coordinators to provide specific information in their 


possession as regards a specific provider of relevant information society interntediary 
services or to exercise their investigative powers referred to in Article 27(1) 5449 with 
regard to specific information located in their Member State. Where appropriate, the 
Coordinating Authority DigitalServices-Coordinator receiving the request may involve 
other competent authorities or other public authorities of the Member State in 
question. 


The Coordinating Authority Digital—Services—Coerdinator receiving the request 


pursuant to paragraph 2 shall comply with such request and inform the requesting 


Coordinating Authority Digital-Services-Coordinator_of-establishment about the action 
taken, without undue delay and-netaterthan two-menths-afterits receipt, unless: 


(a) the scope or the subject matter of the request is not sufficiently specified, 
justified or proportionate in view of the investigative purposes; or 


(b) neither the requested Coordinating Authority Digital-Service—Cooerdinater nor 


other competent authority or other public authority of that Member State is in 
possession of the requested information nor can have access to it; or 


(c) the request cannot be complied with without infringing Union or national law. 


The Digital_Services_Coordinater Coordinating Authority receiving the request shall 


justify its refusal by submitting a reasoned reply, within the period set out in the first 
subparagraph. 


Copied from Article 57 of the DSA (changes vis-a-vis the DSA in italics). 
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Article 39 


GeneraleCooperation, coordination and information-sharing system 


Competent authorities Coordmating—Autherities shall sincerely cooperate with each 
other, ether-competent autherities_of the Member _States_that desicnated the Coordinating 


Authority, the Commission, the EU Centre and other relevant Union agencies, including 
Europol, to facilitate the performance of their respective tasks under this Regulation and to 
ensure its effective, efficient and consistent application and enforcement, without 
prejudice to the possibility for Member States to provide for cooperation mechanisms 
and regular exchanges of views between the competent authorities where relevant for 
the performance of their respective tasks in accordance with this Regulation. 


The authorities and agencies referred to in paragraph 1 may shall, including with the 
support from the EU Centre, coordinate their work for the performance of their 
respective tasks under this Regulation, with a view to ensuring its effective, efficient 


and consistent application and enforcement and avoiding interference with criminal 
investigations in different Member States and te-aveiding duplication of efforts. 


The EU Centre shall establish and maintain one or more reliable and secure information 
sharing systems supporting communications between competent authorities Coordinating 
Authorities, the Commission, the EU Centre, other relevant Union agencies and providers 
of relevant information society services. 


The information sharing system or systems referred to in paragraph 2 shall facilitate 
compliance with the obligations set out in Article 83(2) by enabling automated 


collection eeHecting_in—an—automated—manner and enabling—an easy retrieval 
retrieving of relevant statistical information. 


The competent authorities Coordinatine—Authorities, the Commission, the EU Centre, 
other relevant Union agencies and providers of relevant information society services shall 
use the information-sharing system or systems referred to in paragraph 2 for all relevant 
communications pursuant to this Regulation. 


The Commission shall adopt implementing acts laying down the practical and operational 
arrangements for the functioning of the information-sharing system or systems referred to 
in paragraph 2 and their interoperability with other relevant systems. Those implementing 
acts shall be adopted in accordance with the advisory procedure referred to in Article 87. 
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CHAPTER IV 


EU CENTRE TO PREVENT AND COMBAT CHILD SEXUAL ABUSE 
Section 1 
Principles 
Article 40 
Establishment and scope of action of the EU Centre 


1. A European Union Agency to prevent and combat child sexual abuse, the EU Centre on 
Child Sexual Abuse, is established. 


2: The EU Centre shall contribute to the achievement of the objective of this Regulation by 
supporting and facilitating the implementation of its provisions concerning the detection, 
reporting, removal or disabling of access to, and blocking of online child sexual abuse and 
gather and share information and expertise and facilitate cooperation between relevant 
public and private parties in connection to the prevention and combating of child sexual 
abuse, in particular online. 


Article 41 
Legal status 
1. The EU Centre shall be a body of the Union with legal personality. 
2 In each of the Member States the EU Centre shall enjoy the most extensive legal capacity 


accorded to legal persons under their laws. It may, in particular, acquire and dispose of 
movable and immovable property and be party to legal proceedings. 


2; The EU Centre shall be represented by its Executive Director. 


Article 42 
Seat 


The seat of the EU Centre shall be [The Hague, The Netherlands]*. 


o PCY comment: selection criteria and selection procedure are pending the outcome of 


negotiations on the Anti-Money Laundering Agency. 
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Section 2 


Tasks 
Article 43 
Tasks of the EU Centre 
The EU Centre shall: 
(1) facilitate the risk assessment process referred to in Section 1 of Chapter II, by: 


(a) supporting the Commission in the preparation of the guidelines referred to in Article 
3(8), Article 4(5), Article 6(4) and Article 11, including by collecting and providing 
relevant information, expertise and best practices, taking into account advice from 
the Technology Committee referred to in Article 66; 


(b) upon request from a provider of relevant information services, providing an analysis 
of anonymised data samples for the purpose referred to in Article 3(3); 


(2) facilitate the detection process referred to in Section 2 of Chapter II, by: 
(a) providing the opinions on intended detection orders referred to in Article 7(3), first 
subparagraph, point (d); 
(b) maintaining and operating the databases of indicators referred to in Article 44; 
(c) giving providers of hosting services and providers of interpersonal communications 
services that received a detection order access to the relevant databases of indicators 
in accordance with Article 46; 
(d) making technologies available to providers for the execution of detection orders 
issued to them, in accordance with Article 50(1); 
(3) facilitate the reporting process referred to in Section 3 of Chapter H, by: 
(a) maintaining and operating the database of reports referred to in Article 45; 
(b) assessing, processing and, where necessary, forwarding the reports and providing 
feedback thereon in accordance with Article 48; 
(4) facilitate the removal process referred to in Section 4 of Chapter II and the other processes 
referred to in Section 5, 5a and 6 of that Chapter, by: 
(a) receiving the removal orders transmitted to it pursuant to Article 14(4) in order to 
fulfil the verification function referred to in Article 49(1); 
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(aa) receiving decisions on a cross-border removal order transmitted to it pursuant 
to Article 14a(5); 


(ab) receiving copies of final removal orders and thereto connected information 
transmitted to it pursuant to Article 15(2); 


connection-to intended blocking orders aesteferredto i Attele 162): 


(c) receiving and processing the blocking orders transmitted to it pursuant to Article 
17(3); 


(ca) receiving copies of final blocking orders and thereto connected information 
transmitted to it pursuant to Article 18(2); 


(cb) receiving the delisting orders transmitted to it pursuant to Article 18b(2); 


(cc) receiving copies of final delisting orders and thereto connected information 
transmitted to it pursuant to Article 18c(3); 


(d) providing information and support to victims in accordance with Articles 20 and 21; 


(e) maintaining up-to-date records of contact points and legal representatives of 
providers of relevant information society services as provided in accordance with 
Article 23(2) and Article 24(6); 


(5) support the competent authorities, including the Coordinating Authorities, and the 
Commission in the performance of their tasks under this Regulation and facilitate 
cooperation, coordination and communication in connection to matters covered by this 
Regulation, by: 

(a) creating and maintaining an online register listing the Coordinating Authorities and 
their contact points referred to in Article 25(6); 
(b) providing assistance to the competent authorities Coordinating Authorities free of 
charge and in accordance with its tasks and-obligations under this Regulation as 
ded fori ‘ele 250): 
(c) assisting the Commission, upon its request, in connection to its tasks under the 
cooperation mechanism referred to in Article 37; 
(d) creating, maintaining and operating the information-sharing system referred to in 
Article 39; 
10833/23 FL/ml 83 
ANNEX JAI.1 LIMITE EN 


(6) 


63 


(e) assisting the Commission in the preparation of the delegated and implementing acts 
and the guidelines that the Commission adopts under this Regulation; 


(f) providing information to Coordinating Authorities, upon their request or on its own 
initiative, relevant for the performance of their tasks under this Regulation, including 
by informing the Coordinating Authority of establishment of potential infringements 
identified in the performance of the EU Centre’s other tasks; 


facilitate the generation and sharing of knowledge with other Union institutions, bodies, 
offices and agencies, competent authorities including Coordinating Authorities, or other 
relevant authorities of the Member States to contribute to the achievement of the objective 
of this Regulation, by: 


(a) collecting, recording, analysing and providing information, providing analysis based 
on anonymised and non-personal data gathering, and providing expertise on matters 
regarding the prevention and combating of online child sexual abuse, in accordance 
with Article 51; 


(b) supporting the development and dissemination of research and expertise on those 
matters and on assistance to victims, including by serving as a hub of expertise to 


support evidence-based policy and _by inviting other Union institutions, bodies, 


offices and agencies, competent authorities including Coordinating Authorities, 
or other relevant authorities of the Member States to share information about 


relevant prevention initiatives;~ 


PCY comment: the proposal by a delegation has been integrated in paragraph 6 and in Recital 
60, following the discussion in LEWP of 13 June. The following could be added to recital 
60:““However, for that same reason, the EU Centre should also be charged with certain other 
tasks, notably those relating to the implementation of the risk assessment and mitigation 
obligations of providers of relevant information society services, the removal of or disabling 
of access to child sexual abuse material by providers of hosting services, the provision of 
assistance to Coordinating Authorities, as well as the generation and sharing of knowledge 
and expertise related to online child sexual abuse, including on prevention. The EU Centre 


could, in accordance with its tasks under this Regulation, also assess where possible the 
initiatives related to preventing and combating online child sexual abuse to determine 
whether they can be considered as best practices, using standardised assessment tools 
where possible, and make available these best practices, including through a dedicated 
database, to support the knowledge hub function of the EU Centre and prevent 


duplication of efforts and initiatives, promoting efficiency and collaboration among 
stakeholders.” 


In addition, recital 69 could be amended as follows: “(69) In order to allow for the effective 
and efficient performance of its tasks, the EU Centre should closely cooperate with the 
competent authorities including the Coordinating Authorities, the Europol and relevant 
partner organisations, such as the US National Centre for Missing and Exploited Children, the 
European Crime Prevention Network ((EUCPN’) or the International Association of 
Internet Hotlines ((INHOPE’) network of hotlines for reporting child sexual abuse material, 
within the limits sets by this Regulation and other legal instruments regulating their respective 
activities. To facilitate such cooperation, the necessary arrangements should be made, 
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ba) making available the knowledge referred to in paragraphs (a) and (b) in the 


database referred to in Article 50(4), and in accordance with Article 51; 


(c) drawing up the annual reports referred to in Article 84; 


ion—of—child—sexual_abuse—b 


including the designation of contact officers by Coordinating Authorities and the conclusion 
of EN 36 EN memoranda of understanding with Europol and, where appropriate, with one or 
more of the relevant partner organisations.” 


64__ PCY comment:adelegation has provided-a text proposal for this new point 7 together with 


tees phinatronstereatter 
Pas cpianiae criteria arefromthe dies Crime Prevention ie oe 


‘ope 1 Wiehe other things, Fea een ee oie 
ee 


oes foay pea success. 
e-Fhere should bea robust and pesitive- outcome evahiation, or atleast strong indications-of 
; ‘eal slansibili 


methodology-oftheunderbine evaluation (approach, destin baste patiicteps ete} Tested 
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Article 44 
Databases of indicators 


1. The EU Centre shall create, maintain and operate databases of the following three types of 
indicators of online child sexual abuse: 


(a) indicators to detect the dissemination of child sexual abuse material previously 
detected and identified as constituting child sexual abuse material in accordance with 
Article 36(1); 


(b) indicators to detect the dissemination of child sexual abuse material not previously 
detected and identified as constituting child sexual abuse material in accordance with 
Article 36(1); 


(c) indicators to detect the solicitation of children. 


sae Pee ee ee 


eustonised tothe oa toed preblen aid contest 
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2 The databases of indicators shall solely contain: 


(a) relevant indicators, consisting of digital identifiers to be used to detect the 
dissemination of known or new child sexual abuse material or the solicitation of 
children, as applicable, on hosting services and interpersonal communications 
services, generated by the EU Centre in accordance with paragraph 3; 


(b) as regards paragraph 1, point (a), the relevant indicators shall include a lists of 
uniform resource locators compiled by the EU Centre in accordance with paragraph 
3 for the purpose of, respectively, the issuance of blocking orders in accordance 
with Article 16 and the issuance of delisting orders in accordance with Article 
18a; 


(c) the necessary additional information to facilitate the use of the indicators in 
accordance with this Regulation, including identifiers allowing for a distinction 
between images, videos and, where relevant, other types of material for the detection 
of the dissemination of known and new child sexual abuse material and language 
identifiers for the detection of solicitation of children. 


3. The EU Centre shall generate the indicators referred to in paragraph 2, point (a), solely on 
the basis of the child sexual abuse material and the solicitation of children identified as 
such by the CoerdimatingAuthorties competent authorities of the Member States, 
submitted to it by the Coordinating Authorities pursuant to Article 36(1), point (a), or by 
other competent authorities pursuant to Article 36(1a). 


The EU Centre shall compile the lists of uniform resource locators referred to in paragraph 
2, point (b), solely on the basis of the uniform resource locators submitted to it pursuant to 
Article 36(1), point (b) for the purpose of, respectively, the issuance of blocking orders 
in accordance of Article 16 and the issuance of delisting orders in accordance with 
Article 18a. 


4. The EU Centre shall keep records of the submissions and of the process applied to generate 
the indicators and compile the lists referred to in the first and second subparagraphs. It 
shall keep those records for no longer than asteng-as-the indicators, including the uniform 
resource locators, to which they correspond are contained in the databases of indicators 
referred to in paragraph 1. 


Article 45 
Database of reports 


1. The EU Centre shall create, maintain and operate a database for the reports submitted to it 
by providers of hosting services and providers of interpersonal communications services in 
accordance with Article 12(1) and assessed and processed in accordance with Article 48. 
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De The database of reports shall contain the following information: 
(a) the report; 


(b) where the EU Centre considered the report manifestly unfounded, the reasons and the 
date and time of informing the provider in accordance with Article 48(2); 


(c) where the EU Centre forwarded the report in accordance with Article 48(3), the date 
and time of such forwarding and the name of the competent law enforcement 
authority or authorities to which it forwarded the report or, where applicable, 
information on the reasons for forwarding the report solely to Europol for further 
analysis; 


(d) where applicable, information on the requests for and provision of additional 
information referred to in Article 48(5); 


(e) where available, information indicating that the provider that submitted a report 
concerning the dissemination of known or new child sexual abuse material removed 
or disabled access to the material; 


(f) where applicable, information on the EU Centre’s request to the Ceerdimating 
Authority competent authority of establishment to issue a removal order pursuant to 
Article 14 in relation to the item or items of child sexual abuse material to which the 
report relates; 


(g) relevant indicators and ancillary tags associated with the reported potential child 
sexual abuse material. 


Article 46 
Access, accuracy and security 


1. Subject to paragraphs 2 and 3, solely EU Centre staff and auditors duly authorised by the 
Executive Director shall have access to and be entitled to process the data contained in the 
databases referred to in Articles 44 and 45. 


2 The EU Centre shall give providers of hosting services, providers of interpersonal 
communications services, and providers of internet access services and providers of 
online search engines access to the databases of indicators referred to in Article 44, where 
and to the extent necessary for them to execute the detection or blocking orders that they 
received in accordance with Articles 7 or 16. It shall take measures to ensure that such 
access remains limited to what is strictly necessary for the period of application of the 
detection or blocking orders concerned and that such access does not in any way endanger 
the proper operation of those databases and the accuracy and security of the data contained 
therein. 


By The EU Centre shall give Ceordinating Authorities competent authorities access to the 
databases of indicators referred to in Article 44 where and to the extent necessary for the 
performance of their tasks under this Regulation. 
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The EU Centre shall give Europol and the competent law enforcement authorities of the 
Member States access to the databases of indicators referred to in Article 44 where and to 
the extent necessary for the performance of their tasks of investigating suspected child 
sexual abuse offences®. 


The EU Centre shall give Europol access to the databases of reports referred to in Article 
45, where and to the extent necessary for the performance of its tasks of assisting 
investigations of suspected child sexual abuse offences 


The EU Centre shall provide the access referred to in paragraphs 2, 3, 4 and 5 only upon 
the reception of a request, specifying the purpose of the request, the modalities of the 
requested access, and the degree of access needed to achieve that purpose. The requests for 
the access referred to in paragraph 2 shall also include a reference to the detection order or 
the blocking order, as applicable. 


The EU Centre shall diligently assess those requests and only grant access where it 
considers that the requested access is necessary for and proportionate to the specified 


purpose. 


The EU Centre shall regularly verify that the data contained in the databases referred to in 
Articles 44 and 45 is, in all respects, complete, accurate and up-to-date and continues to be 
necessary for the purposes of reporting, detection and blocking in accordance with this 
Regulation, as well as facilitating and monitoring of accurate detection technologies and 
processes. In particular, as regards the uniform resource locators contained in the database 
referred to Article 44(1), point (a), the EU Centre shall, where necessary in cooperation 
with the Coordination Authorities, regularly verify that the conditions of Article 36(1), 
point (b), continue to be met. Those verifications shall include audits, where appropriate. 
Where necessary in view of those verifications, it shall immediately complement, adjust or 
delete the data. 


The EU Centre shall ensure that the data contained in the databases referred to in Articles 
44 and 45 is stored in a secure manner and that the storage is subject to appropriate 
technical and organisational safeguards. Those safeguards shall ensure, in particular, that 
the data can be accessed and processed only by duly authorised persons for the purpose for 
which the person is authorised and that a high level of security is achieved. The EU Centre 
shall regularly review those safeguards and adjust them where necessary. 


65 PCY comment : the PCY considers it necessary to include a recital outlining possible criteria 
concerning access refusal and justification thereof: “Considering its role as central knowledge 
hub on matters related to the implementation of this Regulation at EU level, the EU Centre 
should, in accordance with this Regulation, leverage all means at its disposal to support the 
work of Europol and competent law enforcement authorities, for example by ensuring that 
information received by law enforcement authorities is relevant, complete and as easy as 
possible to access and consult. In particular, the EU Centre should give Europol and the 
competent law enforcement authorities of the Member States access to the database of 
indicators when necessary for the purpose of their tasks of investigating suspected child 
sexual abuse offences.” 
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Article 47 


Delegated acts relating to the databases 


The Commission shall be empowered to adopt delegated acts in accordance with Article 86 in order 
to supplement this Regulation with the necessary detailed rules concerning: 


(a) 


(b) 


(c) 


(d) 


(c) 


66 
Co 


the types, precise content, set-up and operation of the databases of indicators referred to in 
Article 44(1), including the indicators and the necessary additional information to be 
contained therein referred to in Article 44(2); 


the processing of the submissions by Coordinating Authorities, the generation of the 
indicators, the compilation of the lists of uniform resource locators and the record-keeping, 
referred to in Article 44(3); 


the precise content, set-up and operation of the database of reports referred to in Article 
45(1); 


access to the databases referred to in Articles 44 and 45, including the modalities of the 
access referred to in Article 46(1) to (5), the content, processing and assessment of the 
requests referred to in Article 46(6), procedural matters related to such requests and the 
necessary measures referred to in Article 46(6); 


the regular verifications and audits to ensure that the data contained in those databases is 
complete, accurate and up-to-date referred to in Article 46(7) and the security of the 
storage of the data, including the technical and organisational safeguards and regular 
review referred to in Article 46(8). 


Article 48 
Reporting 


The EU Centre shall expeditiously assess and process reports submitted by providers of 
hosting services and providers of interpersonal communications services in accordance 
with Article 12 to determine whether the reports are manifestly unfounded or are to be 
forwarded. 


Where the EU Centre considers that the report is manifestly unfounded, it shall inform the 
provider that submitted the report, specifying the reasons why it considers the report to be 
unfounded. 


PCY comment: The PCY notes that it has been argued that the empowerment of the 


mmission to adopt delegate acts in this Article may involve essential elements and 


therefore that such elements should be provided directly in the Regulation. 
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ae Where the EU Centre-considersthat there are reasonsable grounds for the EU Centre to 
consider that the a report is netmantfesth-unfounded, it shall forward the report, together 
with any additional relevant information available to it, to Europol and to the competent 
law enforcement authority or authorities of the Member State likely to have jurisdiction to 
investigate or prosecute the potential child sexual abuse to which the report relates. 


Where that competent law enforcement authority or those competent law enforcement 
authorities cannot be determined with sufficient certainty, the EU Centre shall forward the 
report, together with any additional relevant information available to it, to Europol, for 
further analysis and subsequent referral by Europol to the competent law enforcement 
authority or authorities. 


Feport as a mater of priority Bre, wher 


ee. i EE + a 


The EU Centre shall perform the assessment and processing referred to in 
paragraphs 1, 2 and 3 of this Article as a matter of priority in respect of reports 
submitted in accordance with Article 13(2), first subparagraph. In particular, where 
there are reasonable grounds for the EU Centre to consider that the report is founded 
and that there is likely to be an imminent threat to the life or safety of a child 
including when the report indicates ongoing abuse, it shall immediately forward the 
report in accordance with paragraph 3, marking it as requiring urgent action. 


In other cases, Where the EU Centre considers, in respect of a report submitted in 
i ith_Article 13(2), fi } ht} j : likel } 
inert _thrent_tethe tte of a child inehidine hen the +epertdees ot aticate 
engeing—abuse,—it shall forward indicate—that—when—ferwarding the report in 
accordance with paragraph 3 without such marking and it-shal-alse—inform the 
provider that submitted the report and the competent authority, indicating specifying 
in all cases the outcome of the assessment and the reasons explaining that outcome 
vohaiteonsidersthat there is_netHkeh_e bean taniert threat_tethetife oft 

ehild.®* 


=e Where the report does not contain all the information required in Article 13, the EU Centre 
may request the provider that submitted the report to provide the missing information. 


67 PCY comment: while taking note of the concerns on the part of the law enforcement 


community to ensure that Member States receive reasonably substantiated reports, the PCY 
has been made aware that the assessment of potentially complex borderline cases which 
require a detailed assessment of the legality or illegality of the material / conversations in 
question and thus interpretation of national law cannot arguably be a task of the EU Centre 
under the internal market legal basis used in this Regulation. The PCY wishes to hear the 
views of the delegations on this issue. 

PCY comment: the need to explain the concepts “imminent threat” and “ongoing abuse” at 
least in a recital has been raised. 


68 
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Where so requested by a competent law enforcement authority of a Member State in order 
to avoid interfering with activities for the prevention, detection, investigation and 
prosecution of child sexual abuse offences, the EU Centre shall: 


(a) communicate to the provider that submitted the report that it is not to inform the user 
concerned, specifying the time period during which the provider is not to do so; 


(b) where the provider that submitted the report is a provider of hosting services and the 
report concerns the potential dissemination of child sexual abuse material, 
communicate to the provider that it is not to remove or disable access to the material, 
specifying the time period during which the provider is not to do so. 


The time periods referred to in the first subparagraph, points (a) and (b), shall be those 
specified in the competent law enforcement authority’s request to the EU Centre, provided 
that they remain limited to what is necessary to avoid interference with the relevant 
activities and does not exceed 18 months, as_well as constitute necessary and 


proportionate restrictions and respect the essence of the rights of the victims. 


The EU Centre shall verify whether a provider of hosting services that submitted a report 
concerning the potential dissemination of child sexual abuse material removed or disabled 
access to the material, insofar as the material is publicly accessible. Where it considers that 
the provider did not remove or disable access to the material expeditiously, the EU Centre 
shall inform the Coordinating Authority of establishment thereof. 


Article 49 
Searches and notification 


The EU Centre shall have the power to conduct searches on hosting services for the 
dissemination of publicly accessible child sexual abuse material, using the relevant 
indicators from the database of indicators referred to in Article 44(1), points (a) and (b), in 
the following situations: 


(a) where so requested to support a victim by verifying whether the provider of hosting 
services removed or disabled access to one or more specific items of known child 
sexual abuse material depicting the victim, in accordance with Article 21(4), point 


(c); 


(b) where so requested to assist a Coordinatine—Autherty competent authority by 
verifying the possible need for the issuance of a-detection-orderor a removal order in 


respect of a specific service erthe-effectiveness_ofadetection _orderoratemoval 


order that the-Coordinatine Authority issued, in accordance with Article 25(7), points 
(c) and (dj, respectively; 


(c) where so requested to assist a Coordinating Authority, by verifying the 
effectiveness of a detection order that the competent judicial authorities erother 


independent administrative-authorities issued, in accordance with Article 25(7), 
point (d). 
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2: Where-se-requested_te-assist-a-competent-autherity, The EU Centre shall have the power to 


notify, after having conducted the searches referred to in paragraph 1, providers of hosting 
services of the presence of one or more specific items of known child sexual abuse 
material on their services and request them to remove or disable access to that item or 
those items, for the providers’ voluntary consideration. 


The request shall clearly set out the identification details of the EU Centre and a contact 
point, the necessary information for the identification of the item or items, as well as the 
reasons for the request. The request shall also clearly state that it is for the provider’s 
voluntary consideration. 


3; Where so requested by a competent law enforcement authority of a Member State in order 
to avoid interfering with activities for the prevention, detection, investigation and 
prosecution of child sexual abuse offences, the EU Centre shall not submit a notice, for as 
long as necessary to avoid such interference but no longer than 18 months. 


Article 50 
Technologies, information and expertise 


1. The EU Centre shall make available technologies that providers of hosting services and 
providers of interpersonal communications services may acquire, install and operate, free 
of charge, where relevant subject to reasonable licensing conditions, to execute detection 
orders in accordance with Article 10(1). 


To that aim, the EU Centre shall compile lists of such technologies, having regard to the 
requirements of this Regulation and in particular those of Article 10(2). 


Before including specific technologies on those lists, the EU Centre shall request the 
opinion of its Technology Committee and of the European Data Protection Board. The 
Technology Committee and the European Data Protection Board shall deliver their 
respective opinions within eight weeks. That period may be extended by a further six 
weeks where necessary, taking into account the complexity of the subject matter. The 
Technology Committee and the European Data Protection Board shall inform the EU 
Centre of any such extension within one month of receipt of the request for consultation, 
together with the reasons for the delay. 


CD LS A 0 ea ih aia 


requestoftihe Minwcement Bowed ad ia aeccortnce sith the eifes of prececive set 


Where the EU Centre has been requested, in accordance with this Regulation, to 
provide an opinion, information or other assistance on technologies that may be used 
for_ the execution of a_ specific order _issued_under this Regulation, it may, in 
accordance with Article 66, request the Technology Committee for its opinion 
thereon. In that case, the rules of the third paragraph on the time period for 
providing that opinion shall apply. 


10833/23 FL/ml 93 
ANNEX JAL1 LIMITE EN 


The EU Centre shall collect, record, analyse and make available relevant, objective, 
reliable and comparable information on matters related to the prevention and combating of 
child sexual abuse, in particular: 


(a) information obtained in the performance of its tasks under this Regulation 
concerning detection, reporting, removal or disabling of access to, and blocking of 
online child sexual abuse; 


(b) information resulting from the research, surveys and studies referred to in paragraph 
3; 


(c) information resulting from research or other activities conducted by Member States’ 
authorities, other Union institutions, bodies, offices and agencies, the competent 
authorities of third countries, international organisations, research centres and civil 
society organisations. 


Where necessary for the performance of its tasks under this Regulation, the EU Centre 
shall carry out, participate in or encourage research, surveys and studies, either on its own 
initiative or, where appropriate and compatible with its priorities and its annual work 
programme, at the request of the European Parliament, the Council or the Commission. 


The EU Centre shall keep a database encompassing all research, surveys and studies, 
involving public EU or national resources, as referred to in paragraphs 2 and 3 and 


the information resulting thereof._That database shall not contain any personal data 
other than information identifying the authors and any other persons having 
contributed to the research, survey and studies. 


The competent authorities Ht ities may consult this database where 
necessary for the performance of their tasks under this Regulation reference 
PUFPOSES. 


The EU Centre may decide to provide the appropriate level of access for consultation 
of this database to other entities and individuals upon reasoned request, if the 
requesting entities and individuals can justify that such access could contribute to the 
achievement of the objectives of this Regulation. 


The EU Centre shall provide the information referred to in paragraph 2 and the information 
resulting from the research, surveys and studies referred to in paragraph 3, including its 
analysis thereof, and its opinions on matters related to the prevention and combating of 
online child sexual abuse to other Union institutions, bodies, offices and agencies, 
Coordinating Authorities, other competent authorities and other public authorities of the 
Member States, either on its own initiative or at request of the relevant authority. Where 
appropriate, the EU Centre shall make such information publicly available. By-expleiting 


The EU Centre shall develop a communication strategy and promote dialogue with civil 
society organisations and providers of hosting or interpersonal communications services to 
raise public awareness of online child sexual abuse and measures to prevent and combat 
such abuse. 
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Section 3 
Processing of information 
Article 51 


Processing activities and data protection 


1. In so far as is necessary for the performance of its tasks under this Regulation, the EU 
Centre may process personal data. 
2: The EU Centre shall process personal data as strictly necessary for the purposes of: 
(a) providing the opinions on intended detection orders referred to in Article 7(3); 
(b) cooperating with and responding to requests of Coordinating Authorities in 
connection to intended blocking orders as referred to in Article 16(2); 
(c) receiving and processing blocking orders transmitted to it pursuant to Article 17(3); 
(d) cooperating with Coordinating Authorities in accordance with Articles 20 and 21 on 
tasks related to victims’ rights to information and assistance; 
(e) maintaining up-to-date records of contact points and legal representatives of 
providers of relevant information society services as provided in accordance with 
Article 23(2) and Article 24(6); 
(f) creating and maintaining an online register listing the Coordinating Authorities and 
their contact points referred to in Article 25(6); 
(g) providing assistance to Coordinating Authorities in accordance with Article 25(7); 
(h) assisting the Commission, upon its request, in connection to its tasks under the 
cooperation mechanism referred to in Article 37; 
(1) create, maintain and operate the databases of indicators referred to in Article 44; 
(j) | create, maintain and operate the database of reports referred to in Article 45; 
(k) providing and monitoring access to the databases of indicators and of reports in 
accordance with Article 46; 
(1) performing data quality control measures in accordance with Article 46(7); 
(m) assessing and processing reports of potential online child sexual abuse in accordance 
with Article 48; 
(n) cooperating with Europol and partner organisations in accordance with Articles 53 
and 54, including on tasks related to the identification of victims; 
(0) generating statistics in accordance with Article 83. 
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The EU Centre shall store the personal data referred to in paragraph 2 only where and for 
as long as strictly necessary for the applicable purposes listed in paragraph 2. 


It shall ensure that the personal data is stored in a secure manner and that the storage is 
subject to appropriate technical and organisational safeguards. Those safeguards shall 
ensure, in particular, that the personal data can be accessed and processed only for the 
purpose for which it is stored, that a high level of security is achieved and that the personal 
data is deleted when no longer strictly necessary for the applicable purposes. It shall 
regularly review those safeguards and adjust them where necessary. 


Section 4 
Cooperation 
Article 52 
Contact officers 


Each Coordinating Authority shall designate at least one contact officer, who shall be the 
main contact point for the EU Centre in the Member State concerned. The contact officers 
may be seconded to the EU Centre. Where several contact officers are designated, the 
Coordinating Authority shall designate one of them as the main contact officer. 


Contact officers shall assist in the exchange of information between the EU Centre and the 
Coordinating Authorities that designated them. Where the EU Centre receives reports 
submitted in accordance with Article 12 concerning the potential dissemination of new 
child sexual abuse material or the potential solicitation of children, the contact officers 
designated by the competent Member State shall facilitate the process to determine the 
illegality of the material or conversation, in accordance with Article 36(1). 


The Management Board shall determine the rights and obligations of contact officers in 
relation to the EU Centre. Contact officers shall enjoy the privileges and immunities 
necessary for the performance of their tasks. 


Where contact officers are seconded to the EU Centre, the EU Centre shall cover the costs 
of providing them with the necessary premises within the building and adequate support 
for contact officers to perform their duties. All other costs that arise in connection with the 
designation of contact officers and the performance of their tasks shall be borne by the 
Coordinating Authority that designated them. 
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Article 53° 
Cooperation with Europol 


1. Where necessary for the performance of its tasks under this Regulation, within their 
respective mandates, the EU Centre shall cooperate with Europol. 


2, Europol and the EU Centre shall provide each other with the fullest possible access to 
relevant information and information systems, where necessary for the performance of 
their respective tasks and in accordance with the acts of Union law regulating such access. 


Without prejudice to the responsibilities of the Executive Director, the EU Centre shall 
maximise efficiency by sharing administrative functions with Europol, including functions 
relating to personnel management, information technology (IT) and budget 


implementation. 
3: The terms of cooperation and working arrangements shall be laid down in a memorandum 
of understanding”. 
Article 54 
Cooperation with partner organisations 
1. Where necessary for the performance of its tasks under this Regulation, the EU Centre may 


cooperate with organisations and networks with information and expertise on matters 
related to the prevention and combating of online child sexual abuse, including civil 
society organisations and semi-public organisations. 


2 The EU Centre may conclude memoranda of understanding with organisations referred to 
in paragraph 1, laying down the terms of cooperation, including on data sharing. 


69 PCY comment: the PCY noted several questions from delegations on this Article and would 


welcome text proposals from delegations. 
PCY comment: following the changes proposed by the Presidency in Article 62, the 
Management Board is the body that will conclude MoU. 


70 
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Section 5 
Organisation 
Article 55 
Administrative and management structure 
The administrative and management structure of the EU Centre shall comprise: 
(a) a Management Board, which shall exercise the functions set out in Article 57; 
‘ we Board which shall perk ; | ‘elg6d: 


(c) an Executive Director of the EU Centre, who shall exercise the responsibilities set out in 
Article 64; 


(d) a Technology Committee as an advisory group, which shall exercise the tasks set out in 
Article 66. 


Part 1: Management Board 


Article 56 
Composition of the Management Board 


1. The Management Board shall be composed of one representative from each Member State 
and one #we-representatives of the Commission”, all as members with voting rights. 


2. The Management Board shall also include one independent expert observer designated by 
the European Parliament, without the right to vote. 


Europol may designate a representative to attend the meetings of the Management Board 
as an observer on matters involving Europol, without the right to vote, at the request of 
the Chairperson of the Management Board. 


3: Each member of the Management Board shall have an alternate. The alternate shall 
represent the member in his/her absence. 


7” PCY comment: The PCY notes that according to Article 10(1) of the Europol Regulation, 
COM has one representative; according to Article 20(1) of the eu-LISA Regulation, COM has 
two representatives and according to Article 101(1) of the Frontex Regulation, COM has two 
representatives. Given the discussions held in LEWP on this issue, the PCY wishes to hear the 
delegations’ views. 
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4. Members of the Management Board and their alternates shall be appointed in the light of 
their knowledge in the field of combating child sexual abuse, taking into account relevant 
managerial, administrative and budgetary skills. Member States shall appoint a 
representative of their Coordinating Authority, within four months of [date of entry into 
force of this Regulation]. All parties represented in the Management Board shall make 
efforts to limit turnover of their representatives, in order to ensure continuity of its work. 
All parties shall aim to achieve a balanced representation between men and women on the 
Management Board. 


Ds The term of office for members and their alternates shall be four years. That term may be 
renewed. 


Article 57 
Functions of the Management Board” 
1. The Management Board shall: 
(a) give the general orientations for the EU Centre's activities; 


(aa) be responsible for the overall planning and the execution of the tasks conferred 
on the EU Centre pursuant to Article 43, and it shall adopt all the decisions of 


the EU Centre withthe-exception—of the _decisions_that shall be taken_bythe 
Management Board-in-accordance-with Article 57°; 


(b) contribute to facilitate the effective cooperation with and between the Coordinating 
Authorities; 


(c) adopt rules for the prevention and management of conflicts of interest in respect of 
its members, as well as for the members of the Technological Committee and of any 
other advisory group it may establish and publish annually on its website the 
declaration of interests of the members of the Management Board. Fhe-consent-of 


(e) adopt and make public its Rules of Procedure; 


72 ~~ PCY comment: Member States’ comments lead to a direction whereby the Executive Board is 


removed. However, by way of further examining the appropriateness of transferring all the 
tasks of the Executive Board to the Management Board, it may be concluded that an 
Executive Board may be useful for the budgetary and day-to-day management tasks. 
Therefore, an alternative proposal could be that the tasks referred to in Article 62(2) (a), (e), 
(1), (Gj), (m), (n), (0) and (p) are transferred from the Executive Board to the Management 
Board. 

73 Formerly Art 62(1). 
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(f) 


(fa) 


(g) 


(h) 


i) 


(k) 


(I) 


(m) 


appoint the members of the Technology Committee, and of any other advisory group 
it may establish; 


consult the Victims Board in all cases where, in the performance of its tasks 
pursuant to points (a) and (h), interests of victims are concerned; 


adopt the opinions on intended detection orders referred to in Article 7(4), on the 
basis of a draft opinion provided by the Executive Director; 


adopt and regularly update the communication and dissemination plans referred to in 
Article 77(3) based on an analysis of needs. 


adopt, by 30 November of each year-onthe-basis-of-a-_prepesalby_the Executive 
Director, the draft Single Programming Document, and shall transmit it for 


information to the European Parliament, the Council and the Commission by 31 
January the following year, as well as any other updated version of the 
document”; 


adopt the draft annual budget of the EU Centre and exercise other functions in 
respect of the EU Centre’s budget”; 


assess and adopt a consolidated annual activity report on the EU Centre's 
activities, including an overview of the fulfilment of its tasks and send it, by 1 
July each year, to the European Parliament, the Council, the Commission and 
the court of Auditors and make the consolidated annual activity report 
public’®; 


adopt an anti-fraud strategy, proportionate to fraud risks taking into account 
the costs and benefits of the measures to be implemented, an efficiency gains 
and synergies strategy, a strategy for cooperation with third countries and/or 
international organisations, and a strategy for the organisational management 
and internal control systems’; 


exercise, with respect to the staff of the EU Centre, the powers conferred by the 
Staff Regulations on the Appointing Authority and by the Conditions of 
Employment of Other Servants on the EU Centre Empowered to Conclude a 
Contract of Employment” ("the appointing authority powers")”; 


74 Formerly Art 62(2)(a). 

7 Formerly Art 62(2)(b). 

76 Formerly Art 62(2)(c). 

77 Formerly Art 62(2)(d). 

78 Regulation (EEC, Euratom, ECSC) No 259/68 of the Council of 29 February 1968 laying 
down the Staff Regulations of Officials and the Conditions of Employment of Other Servants 
of the European Communities and instituting special measures temporarily applicable to 
officials of the Commission (OJ L 56, 4.3.1968, p. 1) 

79 Formerly Art 62(2)(g). 
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80 
81 
82 
83 
84 
85 
86 
87 
88 


(n) 


(0) 


(p) 


(q) 


(v) 


adopt appropriate implementing rules for giving effect to the Staff Regulations 
and the Conditions of Employment of Other Servants in accordance with 
Article 110(2) of the Staff Regulations®’; 


appoint the Executive Director and remove him/her from office, in accordance 
with Article 65°’; 


appoint an Accounting Officer, who may be the Commission's Accounting 
Officer, subject to the Staff Regulations and the Conditions of Employment of 
other servants, who shall be totally independent in the performance of his/her 
duties*’; 


ensure adequate follow-up to findings and recommendations stemming from the 
internal or external audit reports and evaluations, as well as from investigations 
of the European Anti-Fraud Office (OLAF) ©; 


adopt the financial rules applicable to the EU Centre™; 


take all decisions on the establishment of the EU Centre's internal structures 
and, where necessary, their modification®>; 


appoint a Data Protection Officer®®; 
adopt internal guidelines further specifying the procedures for the processing of 
information in accordance with Article 51, after consulting the European Data 


Protection Supervisor*’; 


authorise the conclusion of memoranda of understanding referred to in Article 
53(3) and Article 54(2) °°. 


With respect to the powers mentioned in paragraph 2 point (m) and (n) ¢g)}-and-(h), 
the Executive-Management Board shall adopt, in accordance with Article 110(2) of 
the Staff Regulations, a decision based on Article 2(1) of the Staff Regulations and 
Article 6 of the Conditions of Employment, delegating relevant appointing authority 
powers to the Executive Director. The Executive Director shall be authorised to sub- 
delegate those powers. 


Formerly Art 62(2)(h). 
Formerly Art 62(2)(i). 
Formerly Art 62(2)(j). 
Formerly Art 62(2)(k). 
Formerly Art 62(2)(1). 
Formerly Art 62(2)(m). 
Formerly Art 62(2)(n). 
Formerly Art 62(2)(0). 
Formerly Art 62(2)(p). 
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In exceptional circumstances, the Exeeutive-Management Board may by way of a 
decision temporarily suspend the delegation of the appointing authority powers to the 
Executive Director and any sub-delegation by the latter and exercise them itself or 
delegate them to one of its members or to a staff member other than the Executive 
Director. 


Article 58 


Chairperson of the Management Board 


1. The Management Board shall elect a Chairperson and a Deputy Chairperson from among 
its members. The Chairperson and the Deputy Chairperson shall be elected by a majority 
of two thirds of the members of the Management Board. 

The Deputy Chairperson shall automatically replace the Chairperson if he/she is prevented 
from attending to his/her duties. 

2. The term of office of the Chairperson and the deputy Chairperson shall be four years. Their 
term of office may be renewed once. If, however, their membership of the Management 
Board ends at any time during their term of office, their term of office shall automatically 
expire on that date. 

a The detailed procedure for the election of the Chairperson and the Vice-Chairperson 
shall be set out in the rules of procedure of the Management Board. 

Article 59 
Meetings of the Management Board 

1. The Chairperson shall convene the meetings of the Management Board. 

2. The Executive Director shall take part in the deliberations, without the right to vote. 

3: The Management Board shall hold at least two ordinary meetings a year. In addition, it 
shall meet on the initiative of its Chairperson, at the request of the Commission, or at the 
request of at least one-third of its members. 

4. The Management Board may invite any person whose opinion may be of interest to attend 
its meetings as an observer, including representatives of the Victims Board. 

ah The members of the Management Board and their alternates may, subject to its rules of 
procedure, be assisted at the meetings by advisers or experts, including representatives of 
the Victims Board. 

6. The EU Centre shall provide the secretariat for the Management Board. 
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Article 60 
Voting rules of the Management Board 


1. Unless provided otherwise in this Regulation, the Management Board shall take decisions 
by absolute majority of its members with voting rights. 


2 Each member shall have one vote. In the absence of a member with the right to vote, 
his/her alternate shall be entitled to exercise his/her right to vote. 


on The Executive Director shall not take part in the voting. 
4. The Management Board's rules of procedure shall establish more detailed voting 


arrangements, in particular the circumstances in which a member may act on behalf of 
another member. 


589. The decisions referred to in Article 57(1), points (c), (j) to (1), (n) to (r) and (v) ma 


only be taken if the representative of the Commission casts a positive vote. For the 

urposes of taking the decisions referred to in Article 57(1), point (i), the consent of 
the representative of the Commission shall only be required on the elements of the 
decision not related to the annual and multi-annual working programme of the EU 
Centre. 


Part 2: Executive Board” 


Article 61 


Compesitien-and_appeintment of the Executive Beard 


the- Management Board avo-other members-appointed-by-the Management Board ffom 


Méaacoment- Beard iio CMbierion-of “the Mannsoment Board shall alsebe-the 


Chaperenotihe Eeeccntive Board 


Fhe Eecettise Director shat parteipate tineetines ot the Ecertive Board stheut the 
rightte-vote- 


89 ~~ PCY comment: the PCY would like to hear the views of delegations on the possibility to give 


veto powers to the Commission in the Management Board only in budgetary matters, if the 
Executive Board is eliminated and all its tasks are transferred to the Management Board. 
PCY comment: Articles 61 to 63 have been deleted but to avoid mistakes in the cross- 
references, Articles 64 to 89 have not been renumbered at this stage. 


90 
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Fasks-of the Executive Board 


SMa ec ee 
7 i gdaan Ghee ; 
{a} co 


(b}— adept the—draft_annual_budget_of the EU —Centre_and_exercise_other_functions—in 
respect of the EU Centre’s budget; 
{e) oo KoA Or Contre’seth ites, 


<a, Gee Ge aaa See ee dl 


systems 


(e}— adept tules_for the _prevention_and management of conflicts_of interest in respect of 
tts4menbers: 


(f}— adeptits tules-of procedure; 
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4)—\appoint the Executive Director and remove him/her from office_in accordance with 
Article-65: 
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5. pine mance! ee 


Article 63 


Voting +ules-of the Executive Board 


Se ieee eas Ga ee The Chairperson shall havea cage voli 
ease-ofatie- 


2 ee ee 


Ariele 202) points(O)40(0) (yet and aes 


Riser ae Adc. sicuedees ‘e-aphich enters re 


anether member. 
Part 3: Executive Director 
Article 64 
Responsibilities of the Executive Director 
1. The Executive Director shall manage the EU Centre. The Executive Director shall be 


accountable to the Management Board. 

2: The Executive Director shall report to the European Parliament on the performance of 
his/her duties when invited to do so. The Council may invite the Executive Director to 
report on the performance of his/her duties. 


3: The Executive Director shall be the legal representative of the EU Centre. 
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The Executive Director shall be responsible for the implementation of the tasks assigned to 
the EU Centre by this Regulation. In particular, the Executive Director shall be responsible 


for: 
(a) 
(b) 
(c) 
(d) 


(c) 


(f) 


(g) 


(h) 


(i) 


Qj) 
(k) 


(I) 


(m) 


the day-to-day administration of the EU Centre; 
preparing decisions to be adopted by the Management Board; 
implementing decisions adopted by the Management Board; 


preparing the Single Programming Document and submitting it to the Exeeutte 
Management Board after consulting the Commission; 


implementing the Single Programming Document and reporting to the Executive 
Management Board on its implementation; 


preparing the Consolidated Annual Activity Report (¢4AR)} on the EU Centre’s 
activities and presenting it to the Exeeuttve Management Board for assessment and 
adoption; 


preparing an action plan following-up conclusions of internal or external audit 
reports and evaluations, as well as investigations by the European Anti-Fraud Office 
(OLAF) and by the European Public Prosecutor’s Office (EPPO) and reporting on 
progress twice a year to the Commission and regularly to the Management Board and 


bd 


protecting the financial interests of the Union by applying preventive measures 
against fraud, corruption and any other illegal activities, without prejudicing the 
investigative competence of OLAF and EPPO by effective checks and, if 
irregularities are detected, by recovering amounts wrongly paid and, where 
appropriate, by imposing effective, proportionate and dissuasive administrative, 
including financial penalties; 


preparing an anti-fraud strategy, an efficiency gains and synergies strategy, a strategy 
for cooperation with third countries and/or international organisations and a strategy 
for the organisational management and internal control systems for the EU Centre 
and presenting them to the Exeeutt-e Management Board for approval; 


preparing draft financial rules applicable to the EU Centre; 


preparing the EU Centre’s draft statement of estimates of revenue and expenditure 
and implementing its budget; 


preparing and implementing an IT security strategy, ensuring appropriate risk 
management for all IT infrastructure, systems and services, which are developed or 
procured by the EU Centre as well as sufficient IT security funding. 


implementing the annual work programme of the EU Centre under the control of the 
Executive Management Board; 
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(n) drawing up a draft statement of estimates of the EU Centre’s revenue and 
expenditure as part of the EU Centre’s Single Programming Document and 
implementing the budget of the EU Centre pursuant to Article 67; 


(0) preparing a draft report describing all activities of the EU Centre with a section on 
financial and administrative matters; 


(p) fostering recruitment of appropriately skilled and experienced EU Centre staff, while 
ensuring gender balance. 


Dn Where exceptional circumstances so require, the Executive Director may decide to locate 
one or more staff in another Member State for the purpose of carrying out the EU Centre’s 
tasks in an a more efficient, effective and coherent manner. Before deciding to establish a 
local office, the Executive Director shall obtain the prior consent of the Commission, the 
Management Board and the Member State concerned. The decision shall be based on an 
appropriate cost-benefit analysis that demonstrates in particular the added value of such 
decision and specify the scope of the activities to be carried out at the local office in a 
manner that avoids unnecessary costs and duplication of administrative functions of the EU 
Centre. A headquarters agreement with the Member State(s) concerned may be concluded. 


6. Without prejudice to the powers of the Commission and of the Management Board 
and_of the Executive Beard, the Executive Director shall be independent in the 
performance of the duties and shall neither seek nor take instructions from any 
government nor from any other body. 


Article 65 
Executive Director 


1. The Executive Director shall be engaged as a temporary agent of the EU Centre under 
Article 2(a) of the Conditions of Employment of Other Servants. 


2 The Executive Director shall be appointed by the Exeeuttve Management Board, from a 
list of candidates proposed by the Commission, following an open and transparent 
selection procedure. 


2. For the purpose of concluding the contract with the Executive Director, the EU Centre 
shall be represented by the Chairperson of the Executive Management Board. 


4. The term of office of the Executive Director shall be five years. Six months before the end 
of the Executive Director’s term of office, the Commission Management Board, with the 
support of the Commission, shall complete an assessment that takes into account an 
evaluation of the Executive Director's performance and the EU Centre's future tasks and 
challenges. 
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la. 


The Executive Management Board, acting on a proposal from the Commission that takes 
into account the assessment referred to in paragraph 3, may extend the term of office of the 
Executive Director once, for no more than five years. 


An Executive Director whose term of office has been extended may not participate in 
another selection procedure for the same post at the end of the overall period. 


The Executive Director may be dismissed only upon a decision of the Executive 
Management Board acting-on-a-propesaltrom the Commission. 


The Exeeuttve Management Board shall take decisions on appointment, extension of the 
term of office or dismissal of the Executive Director by a majority of two-thirds of its 
members with voting rights. 


Subsection 5: Technology Committee 
Article 66 


Establishment and tasks of the Technology Committee 


The Technology Committee shall consist of technical experts appointed by the 


Management Board in view of their excellence, their independence, and particular 
area of expertise, to ensure a conplete gue varied set of skills and capertise the 


view ie es avcollenes and hen =e hee follogane ‘fie BubGauOn of a reall for 
expressions of interest in the Official Journal of the European Union. Member States shall 
appoint nominate twe up to four technical experts each, of which the Management 
Board shall select a maximum of two per Member State while the Commission and 
Europol2s-nnovation-Hub-shall appoint one technical expert each. The Management 
Board may appoint up to eleven additional experts beyond those nominated by 
Member States, or appointed by the Commission and Europol. Fhese-experts-shall be 
selected in view of their excellence and they shall act in the general interest, observing 
the_-principles_of neutrality_and transparency. These experts nominated by Member 
States are not seconded national experts but experts mandated by Member States to 
perform technical expertise missions on _an_ad_hoc_ basis upon request _by the 
Management Board. 


The experts of the Technology Committee shall act in the general interest, observing 
the principles of neutrality and transparency. 


The Technology Committee is shall be divided in seb-working groups specialised in 


assessing specific categories of technologies or types of technologies used to prevent 
and combat fer-the-suppert-of the fight against online child sexual abuse. Fhese Those 
sub-working groups may call on external experts on an ad hoc basis te-assist-withthe 


tasks defined in _points-c) and d) of paragraph 7 


Procedures concerning the appointment of the members of the Technology Committee and 
its operation shall be specified in the rules of procedure of the Management Board and 
shall be made public. 
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92 


- The list of members of the 
Committee shall be made public and shall be updated by the EU Centre on its website. 


When a member no longer meets the criteria of acting in the general interest, neutrality 
or transparency in the framework of his/her mandate independence, he or she shall 
inform the Management Board. Alternatively, the Management Board may declare, on a 
proposal of at least one third of its members or the member appointed by ef the 
Commission, atack-of+ndependence that the member is no longer acting in the general 
interest, or that he or she does not meet the neutrality or eae criteria and 


re the appointment of that member © person concerned, 7 he-Management Bourd 


ere In that case, a renlacement shall be apnointed a the ‘rermudminlluiene of office 
remainder of the mandate of the member concerned in accordance with the procedure 


described in paragraph 1 fer-ordinarymembers. 


The mandates of members of the Technology Committee shall be four years. Those 
mandates shall be renewable once. 


The Technology Committee shall 


(a) contribute to the EU Centre’s opinions referred to in Article 7(3), first subparagraph, 
point (d); 


(b) contribute to the EU Centre’s assistance to the Coordinating Authorities, the 
Management Board, theExeeuttve-Board and the Executive Director, in respect of 
matters related to the use of technology; 


(c) provide internally an-annualexpertise-onthetechnolegicaltoolsmadeavailable 
Pye ey one in the form of an annual guidance report containing the 

°2 upon request, expertise on 

matters related to the use of technology for the purposes of prevention and detection 


of child sexual abuse online; 


(d) provide is See expertise threugh-after having involved the relevant a-sub- 
working group or groups, on an ad hoc basis and at the request of the 


Management Board,—acting by—a—qualified_majority—en—a—prepesal_from—a 
Member State. 


PCY comment: moved to Article 83(3)(k) (new). 
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Article 66a 
Appointment and tasks of the Victims and-Survivers Board 


The Victims and-Survivers Board shall be comprised of adult victims and-survivers 
of child sexual abuse and recognised experts in providing assistance to victims who, 
following a call for expressions of interest published in the Official Journal of the 
European Union, wit shall be appointed by the Management Board on the basis of 
their personal experience, expertise and independence. 


The procedures governing the appointment of the members of the Victims and 
Survivers Board, its functioning and the conditions governing the transmission of 
information to the Victims and-Survivers Board shall be laid down in the 
Management Board’s Rrules of Pprocedure, and shall be published. 


The members of the Victims and-Survivers Board shall be independent in carrying 
out their tasks as members thereof efthe-Beard and shall act in the interest of 
persons-affected_by victims of online child sexual abuse. The EU Centre shall publish 
on its website and keep-up-te-date maintain updated the list of the members of the 
Victims and Survivers Board. 


Members who cease to be independent shall inform the Management Board 
accordingly. Otherwise In addition, the Management Board, at the proposal of at 
least one third of its members or of the member appointed by the Commission, may 
determine that they a given member lacks sufficient independence and revoke their 
appointment. The Management Board shall appoint a replacement new-members-te 
replacethem for the remainder of mandate of the member concerned their 
predecessors”term-of office, following the same procedure as-the-one-governing 
ordinary-mempbers referred to in paragraph 1. 


The term-of office mandate of members of the Victims and-Survivers Board shall be 
four years. It may be renewed once by the Management Board. 


The Executive Director and the Management Board may consult the Victims and 
Survivers Board in connection with all matters concerning persens-affected-by 
victims of online child sexual abuse. 


The Victims and-Survivers Board has the following tasks: 


(a) make the concerns of victims survivers visible heard and_ represent their 
interests in connection to the work of the EU Centre; 


(b) advise the Management Board in matters referred to in Article 57 (1)(fa), 
sentence2; 


(c) advise the Executive Director and the Management Board as—fereseen_ when 
consulted in accordance with paragraph 6; 
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(d) imeorperate contribute their experience and expertise to the work of the EU 
Centre as a knowledge hub as regards preventing and combating online child 
sexual abuse and , assisting and supporting victims; survivers 


fe} _ eat eibite on prepesis ter thes ork ofthe eonipeten it heres: 


(f) contribute to the work of the EU Centre in connection to European networksing 
of victims and-survivers of child sexual abuse. 


Section 6 
Establishment and Structure of the Budget 
Subsection 1 
Single Programming Document 
Article 67 
Budget establishment and implementation 


Each year the Executive Director shall draw up a draft statement of estimates of the EU 
Centre’s revenue and expenditure for the following financial year, corresponding to the 
calendar year, including an establishment plan, and shall send it to the Executive 
Management Board. 


The Exeeutive Management Board shall, on the basis of the draft statement of estimates, 
adopt a provisional draft estimate of the EU Centre’s revenue and expenditure for the 
following financial year and shall send it to the Commission by 31 January each year. 


The Exeeuttve Management Board shall send the final draft estimate of the EU Centre’s 
revenue and expenditure, which shall include a draft establishment plan, to the European 
Parliament, the Council and the Commission by 31 March each year. 


The Commission shall send the statement of estimates to the European Parliament and the 
Council, together with the draft general budget of the Union. 


On the basis of the statement of estimates, the Commission shall enter in the draft general 
budget of the Union the estimates that it considers necessary for the establishment plan and 
the amount of the contribution to be charged to the general budget, which it shall place 
before the European Parliament and the Council in accordance with Articles 313 and 314 
of the Treaty on the Functioning of the European Union. 


The European Parliament and the Council shall authorise the appropriations for the 
contribution from the Union to the EU Centre. 


The European Parliament and the Council shall adopt the EU Centre’s establishment plan. 
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10. 


The EU Centre’s budget shall be adopted by the Exeeuttve Management Board. It shall 
become final following the final adoption of the general budget of the Union. Where 
necessary, it shall be adjusted accordingly. 


The Executive Director shall implement the EU Centre’s budget. 


Each year the Executive Director shall send to the European Parliament and the Council all 
information relevant to the findings of any evaluation procedures. 


Article 68 


Financial rules 


The financial rules applicable to the EU Centre shall be adopted by the Executive Management 
Board after consultation with the Commission. They shall not depart from Delegated Regulation 
(EU) 2019/715* unless such a departure is specifically required for the operation of the EU Centre 
and the Commission has given its prior consent. 


Subsection 2 


Presentation, implementation and control of the budget 


Article 69 
Budget 

1. Estimates of all revenue and expenditure for the EU Centre shall be prepared each financial 
year, which shall correspond to the calendar year, and shall be shown in the EU Centre’s 
budget, which shall be balanced in terms of revenue and of expenditure. 

pd Without prejudice to other resources, the EU Centre’s revenue shall comprise a 
contribution from the Union entered in the general budget of the Union. 

3: The EU Centre may benefit from Union funding in the form of delegation agreements or 
ad hoc grants in accordance with its financial rules referred to in Article 68 and with the 
provisions of the relevant instruments supporting the policies of the Union. 

4. The EU Centre’s expenditure shall include staff remuneration, administrative and 
infrastructure expenses, and operating costs. 

5, Budgetary commitments for actions relating to large-scale projects extending over more 
than one financial year may be broken down into several annual instalments. 

OJ L 122, 10.5.2019, p. 1. 

10833/23 FL/ml 113 

ANNEX JAI.1 LIMITE EN 


Article 70 
Presentation of accounts and discharge 


The EU Centre’s accounting officer shall send the provisional accounts for the financial 
year (year N) to the Commission's accounting officer and to the Court of Auditors by 1 
March of the following financial year (year N + 1). 


The EU Centre shall send a report on the budgetary and financial management for year N 
to the European Parliament, the Council and the Court of Auditors by 31 March of year N 
+1. 


The Commission's accounting officer shall send the EU Centre’s provisional accounts for 
year N, consolidated with the Commission's accounts, to the Court of Auditors by 31 
March of year N + 1. 


The Management Board shall deliver an opinion on the EU Centre’s final accounts for year 
N. 


The EU Centre’s accounting officer shall, by 1 July of year N + 1, send the final accounts 
for year N to the European Parliament, the Council, the Commission, the Court of Auditors 
and national parliaments, together with the Management Board's opinion. 


The final accounts for year N shall be published in the Official Journal of the European 
Union by 15 November of year N + 1. 


The Executive Director shall send to the Court of Auditors, by 30 September of year N + 1, 
a reply to the observations made in its annual report. He or she shall also send the reply to 
the Management Board. 


The Executive Director shall submit to the European Parliament, at the latter's request, any 
information required for the smooth application of the discharge procedure for year N. 


On a recommendation from the Council acting by a qualified majority, the European 
Parliament shall, before 15 May of year N + 2, grant a discharge to the Executive Director 
in respect of the implementation of the budget for year N. 
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Protocol 


Section 7 
Staff 
Article 71 
General provisions 


The Staff Regulations and the Conditions of Employment of Other Servants and the rules 
adopted by agreement between the institutions of the Union for giving effect thereto shall 
apply to the EU Centre for all matters not covered by this Regulation. 


The Executive Management Board, in agreement with the Commission, shall adopt the 
necessary implementing measures, in accordance with the arrangements provided for in 
Article 110 of the Staff Regulations. 


The EU Centre staff, in particular those working in areas related to detection, reporting and 
removal of online child sexual abuse, shall have access to appropriate counselling and 
support services. 


Article 72 
Seconded national experts and other staff 


The EU Centre may make use of seconded national experts or other staff not employed by 
it. 


The Executive Management Board shall adopt rules related to staff from Member States, 
including the contact officers referred to in Article 52, to be seconded to the EU Centre and 
update them as necessary. Those rules shall include, in particular, the financial 
arrangements related to those secondments, including insurance and training. Those rules 
shall take into account the fact that the staff is seconded and to be deployed as staff of the 
EU Centre. They shall include provisions on the conditions of deployment. Where 
relevant, the Exeeuttve Management Board shall aim to ensure consistency with the rules 
applicable to retmbursement of the mission expenses of the statutory staff. 


Article 73 
Privileges and immunities 


No 7 on the Privileges and Immunities of the European Union annexed to the Treaty on the 


Functioning of the European Union shall apply to the EU Centre and its staff. 


Privileges and immunities of contact officers and members of their families shall be subject to an 
agreement between the Member State where the seat of the EU Centre is located and the other 


Member 


States. That agreement shall provide for such privileges and immunities as are necessary 


for the proper performance of the tasks of contact officers. 
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Article 74 
Obligation of professional secrecy 


Members of the Management Board and the Executive Beard_and all members of the staff 
of the EU Centre, including officials seconded by Member States on a temporary basis, and 
all other persons carrying out tasks for the EU Centre on a contractual basis, shall be 
subject to the requirements of professional secrecy pursuant to Article 339 of the Treaty on 
the Functioning of the European Union even after their duties have ceased. 


The Executive Management Board shall ensure that individuals who provide any service, 
directly or indirectly, permanently or occasionally, relating to the tasks of the EU Centre, 
including officials and other persons authorised by the Exeeuttve Management Board or 
appointed by the coordinating authorities for that purpose, are subject to requirements of 
professional secrecy equivalent to those in paragraph 1. 


The EU Centre shall establish practical arrangements for implementing the confidentiality 
rules referred to in paragraphs | and 2. 


The EU Centre shall apply Commission Decision (EU, Euratom) 2015/444%, 
Article 75 
Security rules on the protection of classified and sensitive non-classified information 


The EU Centre shall adopt its own security rules equivalent to the Commission’s security 
rules for protecting European Union Classified Information (EUCI) and sensitive non- 
classified information, as set out in Commission Decisions (EU, Euratom) 2015/443°5 and 
(EU, Euratom) 2015/444. The security rules of the EU Centre shall cover, inter alia, 
provisions for the exchange, processing and storage of such information. The Executive 
Management Board shall adopt the EU Centre’s security rules following approval by the 
Commission. 


Any administrative arrangement on the exchange of classified information with the 
relevant authorities of a third country or, in the absence of such arrangement, any 
exceptional ad-hoc release of EUCI to those authorities, shall be subject to the 
Commission’s prior approval. 


94 


95 


Commission Decision (EU, Euratom) 2015/444 of 13 March 2015 on the security rules for 
protecting EU classified information (OJ L 72, 17.3.2015, p. 53). 

Commission Decision (EU, Euratom) 2015/443 of 13 March 2015 on Security in the 
Commission (OJ L 72, 17.3.2015, p. 41). 
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Section 8 
General provisions 
Article 76 
Language arrangements 


The provisions laid down in Regulation No 1°° shall apply to the EU Centre. The translation 
services required for the functioning of the EU Centre shall be provided by the Translation Centre 
for the bodies of the European Union. 


Article 77 
Transparency and communication 


1. Regulation (EC) No 1049/20019%” shall apply to documents held by the EU Centre. The 
Management Board shall, within six months of the date of its first meeting, adopt the 
detailed rules for applying that Regulation. 


De The processing of personal data by the EU Centre shall be subject to Regulation (EU) 
2018/1725. The Management Board shall, within six months of the date of its first 
meeting, establish measures for the application of that Regulation by the EU Centre, 
including those concerning the appointment of a Data Protection Officer of the EU Centre. 
Those measures shall be established after consultation of the European Data Protection 
Supervisor. 


3: The EU Centre may engage in communication activities on its own initiative within its 
field of competence. Communication activities shall be carried out in accordance with 
relevant communication and dissemination plans adopted by the Management Board. 


°6 Regulation No | determining the languages to be used by the European Economic 


Community (OJ 17, 6.10.1958, p. 385/58). 

97 Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 
2001 regarding public access to European Parliament, Council and Commission documents, 
Official Journal L 145 , 31/05/2001 P. 0043 — 0048. 
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Article 78 
Anti-fraud measures 


In order to combat fraud, corruption and other unlawful activities, Regulation (EU, 
Euratom) No 883/2013°8 shall apply. 


The EU Centre shall accede to the Interinstitutional Agreement of 25 May 1999 between 
the European Parliament, the Council of the European Union and the Commission of the 
European Communities concerning internal investigations by OLAF within six months 
from [date of start of operations as set out in Article 82] and shall adopt the appropriate 
provisions applicable to its staff using the template set out in the Annex to that Agreement. 


The European Court of Auditors shall have the power of audit, on the basis of documents 
and on the spot, over all grant beneficiaries, contractors and subcontractors who have 
received Union funds from the EU Centre. 


OLAF may carry out investigations, including on-the-spot checks and inspections with a 
view to establishing whether there has been fraud, corruption or any other illegal activity 
affecting the financial interests of the Union in connection with a grant or a contract 
funded by the EU Centre, in accordance with the provisions and procedures laid down in 
Regulation (EU, Euratom) No 883/2013 and Council Regulation (Euratom, EC) No 
2185/96". 


Without prejudice to paragraphs 1, 2, 3, and 4, cooperation agreements with third countries 
and international organisations, contracts, grant agreements and grant decisions of the EU 
Centre shall contain provisions expressly empowering the European Court of Auditors and 
OLAF to conduct such audits and investigations, in accordance with their respective 
competences. 


°8 Regulation (EU, Euratom) No 883/2013 of the European Parliament and of the Council of 11 
September 2013 concerning investigations conducted by the European Anti-Fraud Office 
(OLAF) and repealing Regulation (EC) No 1073/1999 of the European Parliament and of the 
Council and Council Regulation (Euratom) No 1074/1999. (OJ L 248, 18.9.2013, p. 1). 


99 


Council Regulation (Euratom, EC) No 2185/96 of 11 November 1996 concerning on-the-spot 


checks and inspections carried out by the Commission in order to protect the European 
Communities' financial interests against fraud and other irregularities. (OJ L 292, 15.11.1996, 


p. 2). 
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Article 79 


Liability 
1. The EU Centre's contractual liability shall be governed by the law applicable to the 
contract in question. 
2, The Court of Justice of the European Union shall have jurisdiction to give judgment 


pursuant to any arbitration clause contained in a contract concluded by the EU Centre. 


3: In the case of non-contractual liability, the EU Centre shall, in accordance with the general 
principles common to the laws of the Member States, make good any damage caused by its 
departments or by its staff in the performance of their duties. 


4. The Court of Justice of the European Union shall have jurisdiction in disputes over 
compensation for damages referred to in paragraph 3. 


2: The personal liability of its staff towards the Centre shall be governed by the provisions 
laid down in the Staff Regulations or Conditions of Employment applicable to them. 


Article 80 
Administrative inquiries 


The activities of the EU Centre shall be subject to the inquiries of the European Ombudsman in 
accordance with Article 228 of the Treaty on the Functioning of the European Union. 


Article 81 
Headquarters Agreement and operating conditions 


1. The necessary arrangements concerning the accommodation to be provided for the EU 
Centre in the Member State where the seat of the EU Centre is located and the facilities to 
be made available by that Member State, together with the specific rules applicable in that 
Member State to the Executive Director, members-ofthe Executive Beard_EU Centre staff 
and members of their families shall be laid down in a Headquarters Agreement between the 
EU Centre and the Member State where the seat of the EU Centre is located, concluded 
after obtaining the approval of the Exeeuthve Management Board and no later than /2 
years after the entry into force of this Regulation]. 


pd The Member State where the seat of the EU Centre is located shall provide the best 
possible conditions to ensure the smooth and efficient functioning of the EU Centre, 
including multilingual, European-oriented schooling and appropriate transport connections. 
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Article 8&2 


Start of the EU Centre's activities 


1. The Commission shall be responsible for the establishment and initial operation of the EU 
Centre until the Executive Director has taken up his or her duties following his or her 
appointment by the Exeeuttve Management Board in accordance with Article 65(2). For 


that purpose: 

(a) the Commission may designate a Commission official to act as interim Executive 
Director and exercise the duties assigned to the Executive Director; !° 

(b) by derogation from Article 62(2)(g) and until the adoption of a decision as referred to 
in Article 62(4), the interim Executive Director shall exercise the appointing 
authority power; 

(c) the Commission may offer assistance to the EU Centre, in particular by seconding 
Commission officials to carry out the activities of the EU Centre under the 
responsibility of the interim Executive Director or the Executive Director; 

(d) the interim Executive Director may authorise all payments covered by appropriations 


100 


entered in the EU Centre's budget after approval by the Executive Management 
Board and may conclude contracts, including staff contracts, following the adoption 
of the EU Centre's establishment plan. 


PCY comment: the PCY would like to hear the views of delegations on the text proposal 


made by one delegation as follows: “(a) the GCormission Member State in charge of the 
Presidency of the Council of the European Union at the time of the creation of the 
Centre may designate in full transparency with Member States a-Commissien in the light 
of their knowledge in the field of combating child sexual abuse taking into account 
relevant managerial, administrative and budgetary skill a senior official to act as interim 
Executive Director and exercise the duties assigned to the Executive Director;” 
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CHAPTER V 


DATA COLLECTION AND TRANSPARENCY REPORTING 
Article §3 


Data collection 


1. Providers of relevant information society services that were subject to orders issued 
under Articles 7, 14, Ida, 16 and 18a Providers of BOrEne services; providers—of 


shall collect 


are on fie falowine topies and pe that information available to a EU Centre upon 
request: 


(a) 


(b) 


(c) 


where the provider has been subject to a detection order issued in accordance with 
Article 7: 


— the measures taken to comply with the order, including the technologies used 
for that purpose and the safeguards provided; 


— the error rates of the technologies deployed to detect online child sexual abuse 
and measures taken to prevent or remedy any errors; 


- in relation to complaints and cases submitted by users in connection to the 
measures taken to comply with the order, the number of complaints submitted 
directly to the provider, the number of cases brought before a judicial authority, 
the basis for those complaints and cases, the decisions taken in respect of those 
complaints and in those cases, the average time needed for taking those 
decisions and the number of instances where those decisions were subsequently 
reversed; 


the number of removal orders and_eress-berder_removal_erders issued to the 
provider in accordance with Articles 14, indicating the number of those orders 
that were subject to he procedure for cross-border removal orders referred to 
in Article 14a. an ne abline-a 
eM 


the total number of items of child sexual abuse material that the provider removed or 
to which it disabled access, broken down by whether the items were removed or 
access thereto was disabled pursuant to a removal order, eress-beorderremeoval 
erder or to a notice submitted by a Competent Authority, the EU Centre or a third 
party or at the provider’s own initiative; 


(d) the number of blocking orders issued to the provider in accordance with Article 16; 
(da) the number of delisting orders issued to the provider in accordance with Article 
18a; 
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(e) the number of instances in which the provider invoked Article 8(3), Article 14(5) or 
(6), et Article 17(4a) or (5) or Article 18b(4) or (5), together with the reasons 
greunds therefor; 
2: Relying to the extent possible on information collected in an automated manner by 


means of the seeure information sharing system or systems referred to in Article 
39(2a), [as well as on any similar system that might be used for the exchange of 
information at national level,] the Coordinating Authorities shall collect data on the 
following topics and make that information available to the EU Centre upon request: 


(a) 


(b) 


(c) 
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the follow-up given to reports of potential online child sexual abuse that the EU 
Centre forwarded in accordance with Article 48(3), specifying for each report:!"! 


whether the report led to the launch of a criminal investigation or contributed 
to an ongoing investigation, ted totakine anyother actionted te ne-action: 


where the report led to the launch of a criminal investigation or contributed to 


an ongoing investigation, the state-of-play-eroutcome of the investigation; ; 


whether victims were identified and rescued and if so their numbers 
differentiating by gender and age, and whether any suspects were arrested 
and any perpetrators were convicted and if so their numbers; 


sehere the-repori ted te as_otheraeton the peat etion the state ef ata ot 
eal id fe teeter 


where no action was taken, the reasons for not taking any action; 


the most important and recurrent risks of online child sexual abuse, as reported by 
providers of hosting services and providers of interpersonal communications services 
in accordance with Article 53 or identified through other information available tethe 


Coordinating Authority; 
a list of the providers of hosting services and providers of interpersonal 


communications services to which the Coordinating Authority addressed a detection 
order in accordance with Article 7; 


PCY comment: the text now provided in the second indent of point (a) is slightly more 


extensive than Article 8 of the Temporary Derogation. Should this Regulation be aligned with 
the Temporary Derogation in this respect? 
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(d) 


(c) 


(f) 


(g) 


(h) 


the number of detection orders issued in accordance with Article 7, broken down by 
provider and by type of online child sexual abuse, and the number of instances in 
which the provider invoked Article 8(3); 


a list of providers of hosting services to which the-Ceordinatine Authority issued a 
removal order er-eress-beorder removal order were was issued in accordance with 


Articles 14 anda; 


the number of removal orders issued in accordance with Article 14, broken down by 
provider, the-time-neededteremove-ordisable_access_te the item oritems_of child 
sexuatabusematertal concerned, and the number of instances in which the provider 
invoked Article 14(5) and (6); 


the number of blocking orders issued in accordance with Article 16, broken down by 
provider, and the number of instances in which the provider invoked Article 17(4a) 
or (5); 


a list of relevant information society services to which the Coordinating 
Authority addressed a decision taken pursuant to Articles 27, 28 or 29, the type 
of decision taken, and the reasons for taking it; 


stbstuntadbhdesated toni the opietef the Coordinate Ate speethaic the 
hick # daginiaanaa Fee the devidtions. 


(ga) the number of complaints received in accordance with Article 34 broken down 


by what the alleged infringement of this Regulation was concerned with and 


Ko cubmided a lain’ 


The EU Centre shall collect data and generate statistics on the detection, reporting, 
removal of or disabling of access to, blocking and delisting of online child sexual abuse 


under this Regulation. The data shall be in particular on the following topics: 


(a) 


(b) 
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the number of indicators in the databases of indicators referred to in Article 44 and 
the development of that number as compared to previous years; 


the number of submissions of child sexual abuse material and solicitation of children 
referred to in Article 36(1), broken down by Member State that designated the 
submitting Coordinating Authorities, and, in the case of child sexual abuse material, 
the number of indicators generated on the basis thereof and the number of uniform 
resource locators included in the list of uniform resource locators in accordance with 
Article 44(3); 


PCY comment: It seems to the PCY that several items in paragraph 3 can only be properly 


assessed and discussed once increased clarity on the outcome of their respective basis is 


reached. 
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(c) the total number of reports submitted to the EU Centre in accordance with Article 12, 
broken down by provider of hosting services and provider of interpersonal 
communications services that submitted the report and by Member State the 
competent authority of which the EU Centre forwarded the reports to in accordance 
with Article 48(3); 


(d) the enlne-child sexual abuse+te—which the reperts_relateinelidinethe-number of 
items of potential known and new child sexual abuse material and instances of 
potential solicitation of children included in the reports the-—Member—Statethe 

forwarded the reports te in accordance 
with Article 48(3), and type of relevant information society service that the reporting 
provider offers; 


(e) the number of reports that the EU Centre considered manifestly unfounded, as 
referred to in Article 48(2); 


(f) the number of reports relating to potential new child sexual abuse material and 
solicitation of children that were assessed as not constituting child sexual abuse 
material of which the EU Centre was informed pursuant to Article 36(3), broken 
down by Member State; 


(g) the results of the searches in accordance with Article 49(1), including the number of 
images, videos and URLs by Member State where the material is hosted; 


(h) where the same item of potential child sexual abuse material was reported more than 
once to the EU Centre in accordance with Article 12 or detected more than once 
through the searches in accordance with Article 49(1), the number of times that that 
item was reported or detected in that manner. 


(1) the number of notices and number of providers of hosting services notified by the EU 
Centre pursuant to Article 49(2); 


(j) number of victims of online child sexual abuse assisted by the EU Centre pursuant to 
Article 21(2), and the number of these victims that requested to receive such 
assistance in a manner accessible to them due to disabilities; 


(k) a report describing the technologies made available by the EU Centre, including 
the published opinions of the European Data Protection Board pursuant to 
Article 50(1). 


4. Providers of relevant information society services that were subject to orders issued 

under Articles 7, 14, 14a, 16 and 18a oe Laan oe SEFVICES; poner of 

Pa es, the 

Coordinate Authorities ice oilier couneeat authorities] and the EU Centre shall 

ensure that the data referred to in paragraphs 1, 2 and 3, respectively, is stored no longer 

than is necessary for the transparency reporting referred to in Article 84. The data stered 
referred to in paragraphs 1 to 3 shall not contain any personal data. 
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ve 


They shall ensure that the data is stored in a secure manner and that the storage is subject 
to appropriate technical and organisational safeguards. Those safeguards shall ensure, in 
particular, that the data can be accessed and processed only for the purpose for which it is 
stored, that a high level of security is achieved and that the information is deleted when no 
longer necessary for that purpose. They shall regularly review those safeguards and adjust 
them where necessary. 


The Commission shall be empowered to adopt delegated acts in accordance with 
Article 86 in order to supplement this Regulation with the necessary detailed rules 
concerning the process of data collection and categorisation of the data to be collected 
pursuant to paragraphs | to 4 for the purposes of follow up of the reports and the 
application of the Regulation. 


Article 84 
Transparency reporting 


Each provider of relevant information society services that were was subject to orders 
issued under Articles 7, 14, 14a, 16 and 18a during the relevant calendar year shall 
draw up an annual report on its activities under this Regulation. That report shall compile 
the information referred to in Article 83(1). The providers shall, by 31 January of every 
year subsequent to the year to which the report relates, make the report available to the 
public and communicate it to the Coordinating Authority of establishment, the 
Commission and the EU Centre. 


Each Coordinating Authority shall draw up an annual report on its activities under this 
Regulation. That report shall compile the information referred to in Article 83(2). It shall, 
by 31 March of every year subsequent to the year to which the report relates, make the 
report available to the public and communicate it to the Commission and the EU Centre. 


Where a Member State has designated several competent authorities pursuant to Article 25, 
it shall ensure that the Coordinating Authority draws up a single report covering the 
activities of all competent authorities under this Regulation and that the Coordinating 
Authority receives all relevant information and support needed to that effect from the other 
competent authorities concerned. 


The EU Centre pen hth ; ; shall draw 
up an annual report on its activities tinder this Regulation. That report shall alse compile 
and analyse the information contained in the reports referred to in paragraphs 2 and Article 
83(3). The EU Centre shall, by 30 June of every year subsequent to the year to which the 
report relates, make the report available to the public and communicate it to the 
Commission. 


The annual transparency reports referred to in paragraphs 1, 2 and 3 shall not include any 
information that may prejudice ongoing activities for the assistance to victims or the 
prevention, detection, investigation or prosecution of child sexual abuse offences. They 
shall alse-not contain any personal data. 


The Commission shall be empowered to adopt delegated acts in accordance with Article 86 
in order to supplement this Regulation with the necessary templates and detailed rules 
concerning the form, precise content and other details of the reports and the reporting 
process pursuant to paragraphs 1, 2 and 3. 
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CHAPTER VI 


FINAL PROVISIONS 
Article 85 
Evaluation 


By [five years after the entry into force of this Regulation], and every five years thereafter, 
the Commission shall evaluate this Regulation and submit a report on its application to the 
European Parliament and the Council. 


By [five years after the entry into force of this Regulation], and every five years thereafter, 
the Commission shall ensure that an evaluation in accordance with Commission guidelines 
of the EU Centre’s performance in relation to its objectives, mandate, tasks and 
governance and location is carried out. The evaluation shall, in particular, address the 
possible need to modify the tasks of the EU Centre, and the financial implications of any 
such modification. 


On the occasion of every second evaluation referred to in paragraph 2, the results achieved 
by the EU Centre shall be assessed by the Commission, having regard to it?s the EU 
Centre’s objectives and tasks, including an assessment of whether the continuation of the 
EU Centre is still justified with regard to those objectives and tasks. 


The Commission shall report to the European Parliament and the Council the findings of 
the evaluation referred to in paragraph 3. The findings of the evaluation shall be made 
public. 


For the purpose of carrying out the evaluations referred to in paragraphs 1, 2 and 3, the 
Coordinating Authorities and Member States and the EU Centre shall provide information 
to the Commission at its request. 


In carrying out the evaluations referred to in paragraphs 1, 2 and 3, the Commission shall 
take into account the relevant evidence at its disposal. 


Where appropriate, the reports referred to in paragraphs 1 and 4 shall be accompanied by 
legislative proposals. 
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103 


Article 86 
Exercise of the delegation 


The power to adopt delegated acts is conferred on the Commission subject to the 
conditions laid down in this Article. 


The power to adopt delegated acts referred to in Articles 3, 8, 13, 14, 17, 47 and 84 shall be 
conferred on the Commission for an indeterminate period of time from [date of adoption of 
the Regulation] '°. 


The delegation of power referred to in Articles 3, 8, 13, 14, 17, 47 and 84 may be revoked 
at any time by the European Parliament or by the Council. A decision to revoke shall put 
an end to the delegation of the power specified in that decision. It shall take effect the day 
after the publication of the decision in the Official Journal of the European Union or at a 
later date specified therein. It shall not affect the validity of any delegated acts already in 
force. 


Before adopting a delegated act, the Commission shall consult experts designated by each 
Member State in accordance with the principles laid down in the Inter-institutional 
Agreement of 13 April 2016 on Better Law-Making. 


As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the 
European Parliament and to the Council. 


A delegated act adopted pursuant to Articles 3, 8, 13, 14, 17, 47 and 84 shall enter into 
force only if no objection has been expressed either by the European Parliament or the 
Council within a period of two months of notification of that act to the European 
Parliament and the Council or if, before the expiry of that period, the European Parliament 
and the Council have both informed the Commission that they will not object. That period 
shall be extended by two months at the initiative of the European Parliament or of the 
Council. 


PCY comment: The PCY has taken note of the comment from some delegations that the 


delegation in relation to Article 47 is concerned with subject-matters that may not be 
appropriate for such delegation due to its principal nature. The PCY suggests that this 
particular issue is discussed in connection with Article 47 and, where needed, in connection 
with the other Articles referred to here. 
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Article 87 
Committee procedure 
1. For the purposes of the adoption of the implementing acts referred to in Article 39(4), the 


Commission shall be assisted by a committee. That committee shall be a committee within 
the meaning of Regulation (EU) No 182/2011. 


2 Where reference is made to this paragraph, Article 4 of Regulation (EU) No 182/2011 shall 
apply. 
Article 881% 
Repeal 


Regulation (EU) 2021/1232 is repealed from [date of application of this Regulation]. 
Article 89 


Entry into force and application 


This Regulation shall enter into force on the twentieth day following that of its publication in the 
Official Journal of the European Union. 


It shall apply from 18 6months after its entry into force. 


This Regulation shall be binding in its entirety and directly applicable in all Member States. 


Done at Brussels, 


For the European Parliament For the Council 


The President The President 


104 PCY comment: Many delegations are in favour of exploring how the Temporary Regulation 


could be prolonged and/or how to allow voluntary detection on a permanent basis by 
including the provisions of the Temporary Regulation in this Regulation. It has also been 
proposed to apply certain provisions of the Regulation before the bulk of the Regulation will 
be applicable. This includes key provisions such as on the designation of competent 
authorities and initiating work on risk assessment. 


10833/23 FL/ml 128 
ANNEX JALI LIMITE EN 


ANNEX 


Article 27 [clean version of former Art 27-30] 
Investigatory and enforcement powers 


1. Where needed in order to carrying out their tasks under this Regulation, competent 
authorities shall have the following powers of investigation, in respect of conduct by 
providers of relevant information society services under the jurisidiction of their Member 
State: 


(a) the power to require those providers, as well as any other persons acting for purposes 
related to their trade, business, craft or profession that may reasonably be aware of 
information relating to a suspected infringement of this Regulation, to provide such 
information without undue delay; 


(b) the power to carry out, or to request a judicial authority to order, inspections of any 
premises that those providers or those persons use for purposes related to their trade, 
business, craft or profession, or to request other public authorities to do so, in order 
to examine, seize, take or obtain copies of information relating to a suspected 
infringement in any form, irrespective of the storage medium; 


(c) the power to ask any member of staff or representative of those providers or those 
persons to give explanations in respect of any information relating to a suspected 
infringement and to record the answers by any technical means; 


(d) the power to request information, including to assess whether the measures taken to 
execute a detection order, removal order, blocking order or delisting order comply 
with the requirements of this Regulation. 


2. Where needed for carrying out their tasks under this Regulation, competent authorities 
shall have the following enforcement powers, in respect of providers of relevant 
information society services under the juridiction of their Member State: 


(a) the power to accept the commitments offered by those providers in relation to their 
compliance with this Regulation and to make those commitments binding; 


(b) | the power to order the cessation of infringements and, where appropriate, to impose 
remedies proportionate to the infringement and necessary to bring the infringement 
effectively to an end or to request a judicial authority to do so; 


(c) the power to impose fines, or request a judicial authority in their Member State to do 
so, in accordance with Article 35 for failure to comply with this Regulation, 
including any of the investigative orders issued pursuant to paragraph 1 of this 
Article; 
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(d) the power to impose a periodic penalty payment, or to request a judicial authority to 
do so, in accordance with Article 35 to ensure that an infringement is terminated in 
compliance with an order issued pursuant to point (b) of this subparagraph or for 
failure to comply with any of the orders issued pursuant to paragraph | of this 
Article. 


(e) the power to adopt interim measures or to request the competent national judicial 
authority to do so, to avoid the risk of serious harm. 


As regards the first subparagraph, points (c) and (d), competent authorities shall also have 
the enforcement powers set out in those points in respect of the other persons referred to in 
paragraph 1, for failure to comply with any of the orders issued to them pursuant to that 
paragraph. They shall only exercise those enforcement powers after having provided those 
other persons in good time with all relevant information relating to such orders, including 
the applicable period, the fines or periodic payments that may be imposed for failure to 
comply and the possibilities for redress. 


Where needed for carrying out their tasks under this Regulation, competent authorities 
shall, in respect of providers of relevant information society services under the jurisdiction 
of their Member State, where all other powers pursuant to this Article to bring about the 
cessation of an infringement have been exhausted and the infringement has not been 
remedied or is continuing and is eausing serious harm which cannot be avoided through the 
exercise of other powers available under Union or national law, also have the power to take 
the following measures: 


(a) to require the management body of the providers, without undue delay, to examine 
the situation, to adopt and submit an action plan setting out the necessary measures to 
terminate the infringement, to ensure that the provider takes those measures, and to 
report on the measures taken; 


(b) where the competent authorities, including the Coordinating Authorities consider that 
a provider of relevant information society services has not sufficiently complied with 
the requirements of point (a), that the infringement has not been remedied or is 
continuing and is causing serious harm, and that that infringement entails a criminal 
offence involving a threat to the life or safety of persons or the infringement results 
in the regular and structural facilitation of child sexual abuse offences, to request that 
the competent judicial authority ex-etherindependent-administrative-autherity of its 
Member State order the temporary restriction of access of users of the service 
concerned by the infringement or, only where that is not technically feasible, to the 
online interface of the provider on which the infringement takes place. 


The competent authorities, including the Coordinating Authorities, shall, prior to 
submitting the request referred to in this paragraph, point (b), invite interested parties to 
submit written observations within a period that shall not be less than two weeks, 
describing the measures that it intends to request and identifying the intended addressee or 
addressees thereof. The provider, the intended addressee or addressees and any other third 
party demonstrating a legitimate interest shall be entitled to participate in the proceedings 


before the competent judicial authority eretherindependent administrative authority. 
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Any measure ordered shall be proportionate to the nature, gravity, recurrence and duration 
of the infringement, without unduly restricting access to lawful information by users of the 
service concerned. 


The restriction of access shall be for a period of four weeks, subject to the possibility for 
the competent judicial authority eretherindependent-administrative—autherity of the 
Member State, in its order, to allow the competent authorities to extend that period for 
further periods of the same lengths, subject to a maximum number of extensions set by a 


that judicial authority or-otherindependent administrative-authority. 


The competent authorities referred to in the previous subparagraph shall only extend the 
period where, having regard to the rights and interests of all parties affected by that 
restriction and all relevant circumstances, including any information that the provider, the 
addressee or addressees and any other third party that demonstrated a legitimate interest 
may provide to it, it considers that both of the following conditions have been met: 


(a) the provider has failed to take the necessary measures to terminate the infringement; 


(b) the temporary restriction does not unduly restrict access to lawful information by 
users of the service, having regard to the number of users affected and whether any 
adequate and readily accessible alternatives exist. 


Where the competent authority considers that the conditions set out in the fourth 
subparagraph, points (a) and (b) have been met but it cannot further extend the period 
pursuant to the fourth subparagraph, it shall submit a new request to the competent judicial 


authority er—other—independent—administratrre—autherity, as referred to in the first 
subparagraph, point (b). 


The measures taken by the competent authorities, including the Coordinating Authorities, 
in the exercise of their powers listed in paragraphs 1, 2 and 3 shall be effective, dissuasive 
and proportionate, having regard, in particular, to the nature, gravity, recurrence and 
duration of the infringement or suspected infringement to which those measures relate, as 
well as the economic, technical and operational capacity of the provider of relevant 
information society services concerned; where relevant. 


Member States shall lay down specific rules and procedures for the exercise of the powers 
pursuant to paragraphs 1, 2 and 3 and shall ensure that any exercise of those powers is 
subject to adequate safeguards laid down in the applicable national law in compliance with 
the Charter and with the general principles of Union law. In particular, those measures 
shall only be taken in accordance with the right to respect for private life and the rights of 
defence, including the rights to be heard and of access to the file, and subject to the right to 
an effective judicial remedy of all affected parties. 
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ANNEX 


Following the new governance model concerning Coordinating Authorities and competent 
authorities, tasks can now be attributed to any competent authority, unless it is specified that they 
should be reserved for Coordinating Authorities. 


Coordinating Authorities are competent authorities acting as contact points and coordinating bodies 
at national and EU level. 


Coordination at national level entails the centralisation of information concerning the 
implementation of the regulation, and the handling of complaints on its infringement. In particular, 
the following tasks are reserved for Coordinating Authorities: 


O 


Receiving copies of all final removal, blocking orders and delisting orders issued by 
competent authorities in their Member State of establishment; 


Handling complaints for infringements of the Regulation under Article 34; 


Receiving extracts of conversations and items of materials identified as constituting 
online CSA by competent authorities in their Member State of establishment in 
accordance with Article 36; 


Transmitting copies of cross-border removal orders received from other Member States 
to the competent authority in their Member State of establishment, if needed; 


Collecting the information referred to in Article 83(2) in relation to their Member State 
of establishment, with the cooperation of all national competent authorities; 


Direct exchanges between Coordinating Authorities and service providers or between 
Coordinating Authorities and victims; 


Supervision of Articles 3 (risk assessment), 4 (risk mitigation), 5 (risk reporting), 6 
(obligations for software application stores) as well as the power of initiative of 
Coordinating Authorities to obtain the issuance of a detection order (Article 7) and the 
application of Articles 9 (modification of detection orders) and 10 (technologies and 
safeguards); 


The appointment of a contact officer for the EU Centre; 


The appointment of a representative of the Coordinating Authorities to sit on the Board 
of Directors; 


The drafting of an annual activity report. 
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Coordination at EU level entails (i) channelling of information gathered in their Member State of 
establishment to other Coordinating Authorities and the EU Centre, (ii) cooperating with these 
authorities, as well as with the Commission, and (iii) dispatching the information coming from the 
EU Centre and other Coordinating Authorities to other competent authorities in their Member State 
of establishment. In particular, the following tasks are reserved for Coordinating Authorities: 


o Coordinating with Commission and EU Centre for the issuance of guidelines on detection 
and reporting under Articles 11 and 12. 


o Receiving copies of cross-border removal orders from Coordinating Authority of issuing 
Member State (14(a)(1)). 


o Transmitting copy of final removal, blocking and delisting orders issued in their Member 
State to all other Competent Authorities and EU Centre 


o Submitting items of materials, transcripts extracts of written conversations and exact 
uniform resource locators to the EU Centre in accordance with Article 36(1), as well as 
providing further clarifications and information to the EU Centre if needed, in accordance 
with Article 36(2). 


o Submitting requests for cross border cooperation in accordance with Article 37(1), receiving 
the Commission recommendations in line with the same paragraph and communicating the 
outcome of the assessment of the suspected infringement in accordance with Article 37(4). 


o Participating in joint investigations in accordance with Article 38. 
o Exchanging information with other Coordinating Authorities under Article 38a 


o Communicating with other Coordinating Authorities, the Commission, the EU Centre and 
other relevant Union agencies through the reliable and secure information sharing system 
referred to in Article 39(2). 


o Making available to the EU Centre the information referred in Article 83(2). 


10833/23 FL/ml 133 
ANNEX JALI LIMITE EN 


